Field Assessment
AI analysis pending.
CVE
CVE-2017-9303
Severity
MEDIUM
CVSS
6.1
EPSS
0.96%
Original Filing — NVD Description
Laravel 5.4.x before 5.4.22 does not properly constrain the host portion of a password-reset URL, which makes it easier for remote attackers to conduct phishing attacks by specifying an attacker-controlled host.