This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
Pentest-Tools.com
pentest-tools.com
did:plc:rdesfgypi36dlzlnlxze7vdp
FuelCMS trusts whatever Host header you send it.
Spoof it on a password reset request → victim gets a legit-looking email → clicks the link → token goes to you.
PTT-2025-029 / CVE-2026-30459, CVSS 7.1 High. No fix coming.
Full PoC 👇
pentest-tools.com/research
2026-04-16T11:56:30.722Z