{"id":"GHSA-75x2-6h4m-h6mx","summary":"FullStackHero's WebAPI Boilerplate host header injection vulnerability","details":"A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackers to leak the password reset token via a crafted request.","aliases":["CVE-2024-26470"],"modified":"2024-11-28T05:40:21.657977Z","published":"2024-02-29T03:33:18Z","database_specific":{"nvd_published_at":"2024-02-29T01:44:18Z","cwe_ids":["CWE-200"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-03-01T16:56:37Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-26470"},{"type":"WEB","url":"https://github.com/dub-flow/vulnerability-research/tree/main/CVE-2024-26470"},{"type":"PACKAGE","url":"https://github.com/fullstackhero/dotnet-webapi-boilerplate"},{"type":"WEB","url":"https://www.nuget.org/packages/FullStackHero.WebAPI.Boilerplate"}],"affected":[{"package":{"name":"FullStackHero.WebAPI.Boilerplate","ecosystem":"NuGet","purl":"pkg:nuget/FullStackHero.WebAPI.Boilerplate"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"last_affected":"1.0.1"}]}],"versions":["1.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-75x2-6h4m-h6mx/GHSA-75x2-6h4m-h6mx.json"}}],"schema_version":"1.9.0"}