Beveiligingsadvies

CVE-2024-26470

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-02-27 00:00:00
Laatst bijgewerkt 2024-08-28 15:41:54
Toegewezen door mitre
CVSS-score 8.1
Status PUBLISHED

Beschrijving

A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackers to leak the password reset token via a crafted request.