CVE-2024-26470

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-26470
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26470.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-26470
Aliases
Published
2024-02-29T01:44:18Z
Modified
2025-05-17T14:04:43.428728Z
Summary
[none]
Details

A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackers to leak the password reset token via a crafted request.

References

Affected packages

Git / github.com/fullstackhero/dotnet-webapi-boilerplate

Affected ranges

Type
GIT
Repo
https://github.com/fullstackhero/dotnet-webapi-boilerplate
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

0.*

0.0.1-rc
0.0.3-rc
0.0.4-rc
0.0.5-rc
0.0.6-rc

1.*

1.0.0