← Vulnerability feed

Vulnerability record · CVE-2016-10073 · published 23 May 2017

CVE-2016-10073: Vanilla Forums email domain spoofing via Host header

Vanillaforums · Vanilla

The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 trusts the HTTP Host header when constructing the sender address of outgoing mail. An unauthenticated remote attacker can therefore spoof the email domain in messages the forum sends, including password reset emails, which can leak sensitive information such as reset tokens.

7.5 CVSS 3.0 High EPSS 84% · top 0.3% CWE-200 · Information exposure
7.5CVSS 3.0 base score, v2 5.0
84%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent messages and potentially obtain sensitive information via a crafted HTTP Host header, as demonstrated by a password reset request.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityUnauthenticated remote exploitation is trivial and public exploit code exists, with very high EPSS, though the direct impact is information exposure rather than code execution.

What it is

The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 trusts the HTTP Host header when constructing the sender address of outgoing mail. An unauthenticated remote attacker can therefore spoof the email domain in messages the forum sends, including password reset emails, which can leak sensitive information such as reset tokens.

Impact

An attacker can send forum-originated email that appears to come from an arbitrary domain, enabling phishing and interception of password reset links or tokens that may expose user accounts.

Attack surface

Reachable over the network by sending a crafted HTTP Host header to the forum; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.836, 99.7th percentile) and multiple references are tagged Exploit, including a public exploit writeup and Exploit-DB entry.

What to do

  • Upgrade Vanilla Forums to 2.3.1 or later, which the vendor advisory marks as the critical security release fixing this issue.
  • Configure the web server to enforce a fixed, validated Host header and reject requests with unexpected Host values.
  • Do not rely on the Host header for generating links or sender addresses; hardcode the canonical forum domain in application configuration where possible.
  • Invalidate or shorten the lifetime of outstanding password reset tokens and monitor for reset abuse.
  • Restrict outbound mail to a controlled relay and monitor for messages with unexpected sender domains.

Detection

  • Inspect web server and application logs for requests with anomalous or attacker-controlled Host headers.
  • Monitor outbound mail logs for sender domains that do not match the legitimate forum domain.
  • Alert on spikes in password reset requests or reset emails sent to unusual recipients.
  • Review mail queue and SMTP logs for messages generated shortly after suspicious Host header requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-10073 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2011-3614Vanillaforums vanilla vulnerabilityAn Access Control vulnerability exists in the Facebook, Twitter, and Embedded plugins in Vanilla Forums before 2.0.17.9.EPSS 2.0%9.8CVE-2018-18903Vanillaforums vanilla code injection vulnerabilityVanilla 2.6.x before 2.6.4 allows remote code execution.EPSS 5.2%7.5CVE-2011-3613Vanillaforums vanilla information exposure vulnerabilityAn issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled.EPSS 1.7%7.5CVE-2013-3527Vanillaforums vanilla sql injection vulnerabilityMultiple SQL injection vulnerabilities in Vanilla Forums before 2.0.18.8 allow remote attackers to execute arbitrary SQL commands via the parameter n…EPSS 3.5%7.5CVE-2013-3528Vanillaforums vanilla vulnerabilityUnspecified vulnerability in the update check in Vanilla Forums before 2.0.18.8 has unspecified impact and remote attack vectors, related to "object …EPSS 5.7%7.2CVE-2018-19499Vanillaforums vanilla deserialization of untrusted data vulnerabilityVanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a reachable call to unserialize in…EPSS 2.0%6.5CVE-2018-16410Vanillaforums vanilla sql injection vulnerabilityVanilla before 2.6.1 allows SQL injection via an invitationID array to /profile/deleteInvitation, related to applications/dashboard/models/class.invi…EPSS 0.94%6.4CVE-2011-0910Vanillaforums vanilla vulnerabilityThe cookie implementation in Vanilla Forums before 2.0.17.6 makes it easier for remote attackers to spoof signed requests, and consequently obtain ac…EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2016-10073), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.