Vulnerability record · CVE-2016-10073 · published 23 May 2017
CVE-2016-10073: Vanilla Forums email domain spoofing via Host header
Vanillaforums · Vanilla
The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 trusts the HTTP Host header when constructing the sender address of outgoing mail. An unauthenticated remote attacker can therefore spoof the email domain in messages the forum sends, including password reset emails, which can leak sensitive information such as reset tokens.
Description
The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent messages and potentially obtain sensitive information via a crafted HTTP Host header, as demonstrated by a password reset request.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated remote exploitation is trivial and public exploit code exists, with very high EPSS, though the direct impact is information exposure rather than code execution.
What it is
The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 trusts the HTTP Host header when constructing the sender address of outgoing mail. An unauthenticated remote attacker can therefore spoof the email domain in messages the forum sends, including password reset emails, which can leak sensitive information such as reset tokens.
Impact
An attacker can send forum-originated email that appears to come from an arbitrary domain, enabling phishing and interception of password reset links or tokens that may expose user accounts.
Attack surface
Reachable over the network by sending a crafted HTTP Host header to the forum; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.836, 99.7th percentile) and multiple references are tagged Exploit, including a public exploit writeup and Exploit-DB entry.
What to do
- Upgrade Vanilla Forums to 2.3.1 or later, which the vendor advisory marks as the critical security release fixing this issue.
- Configure the web server to enforce a fixed, validated Host header and reject requests with unexpected Host values.
- Do not rely on the Host header for generating links or sender addresses; hardcode the canonical forum domain in application configuration where possible.
- Invalidate or shorten the lifetime of outstanding password reset tokens and monitor for reset abuse.
- Restrict outbound mail to a controlled relay and monitor for messages with unexpected sender domains.
Detection
- Inspect web server and application logs for requests with anomalous or attacker-controlled Host headers.
- Monitor outbound mail logs for sender domains that do not match the legitimate forum domain.
- Alert on spikes in password reset requests or reset emails sent to unusual recipients.
- Review mail queue and SMTP logs for messages generated shortly after suspicious Host header requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/142486/Vanilla-Forums-2.3-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://exploitbox.io/vuln/Vanilla-Forums-Exploit-Host-Header-Injection-CVE-2016-10073-0day.html | ExploitThird Party Advisory |
| https://open.vanillaforums.com/discussion/33498/critical-security-release-vanilla-2-3-1 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/41996/ | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/142486/Vanilla-Forums-2.3-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://exploitbox.io/vuln/Vanilla-Forums-Exploit-Host-Header-Injection-CVE-2016-10073-0day.html | ExploitThird Party Advisory |
| https://open.vanillaforums.com/discussion/33498/critical-security-release-vanilla-2-3-1 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/41996/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2016-10073 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-10073), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.