MEDIUM🇵🇱 Wersja polska

CVE-2025-50579

CVSS 5.3v3.1pub. 2025-08-19upd. 2025-09-24

A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particularly JWT tokens, due to improper validation of the Origin header. This misconfiguration enables attackers to intercept tokens using a simple browser script and exfiltrate them to a remote attacker-controlled server, potentially leading to unauthorized actions within the application.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  • Jc21 nginx Proxy Manager

    APP
    Jc21
    2.12.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-46256CRITICAL9.8PL ✓same product

Command injection w Nginx Proxy Manager — RCE przez funkcję Let's Encrypt

CVE-2023-27224CRITICAL9.8PL ✓same product

RCE w NginxProxyManager przez wstrzyknięcie skryptu Lua do konfiguracji

CVE-2024-39935HIGH8.8same product

jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authe...

CVE-2023-23596HIGH8.8same product

jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend...

CVE-2024-46257MEDIUM6.3same product

A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows ...