medium · CVSS v3 6.1 · CVSS v4 5.3
CVE-2026-105117
OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control …
Description
OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control notification email wording via the forgotPassword and register actions on /json/{realm}/users. Attackers can supply subject and message fields to send phishing mail from the organisation's configured From address, or abuse register as a relay to arbitrary recipients.
Scores
- Severity
- medium
- CVSS v2
- 6.4
- CVSS v3
- 6.1
- CVSS v4
- 5.3
- EPSS
- —