CVE-2016-10073 | Vanilla Forums up to 2.3.0 Password Reset class.email.php from HTTP Host Header information disclosure (EDB-41996 / Nessus ID 104659)
A vulnerability was found in Vanilla Forums up to 2.3.0 and classified as problematic. Affected by this issue is the function from of the file library/core/class.email.php of the component Password Reset. The manipulation as part of HTTP Host Header leads to information disclosure.
This vulnerability is handled as CVE-2016-10073. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.