CVE-2024-26470

Publication date

2024-02-27 00:00:00

Family

mitre

State

PUBLISHED

Description

A host header injection vulnerability in the forgot password function of FullStackHeros WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackers to leak the password reset token via a crafted request.