CVE Vulnerabilities

CVE-2024-26470

Published: Feb 29, 2024 | Modified: Feb 29, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A host header injection vulnerability in the forgot password function of FullStackHeros WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackers to leak the password reset token via a crafted request.

References