2024-02-29 03:01:19 +00:00
{
"id" : "CVE-2024-26470" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2024-02-29T01:44:18.927" ,
2024-02-29 15:04:26 +00:00
"lastModified" : "2024-02-29T13:49:29.390" ,
"vulnStatus" : "Awaiting Analysis" ,
2024-02-29 03:01:19 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackers to leak the password reset token via a crafted request."
}
] ,
"metrics" : { } ,
"references" : [
{
"url" : "https://github.com/dub-flow/vulnerability-research/tree/main/CVE-2024-26470" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://github.com/fullstackhero/dotnet-webapi-boilerplate" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://www.nuget.org/packages/FullStackHero.WebAPI.Boilerplate" ,
"source" : "cve@mitre.org"
}
]
}