Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackers to leak the password reset token via a crafted request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
FullStackHero WebAPI Boilerplate 安全漏洞
Vulnerability Description
FullStackHero WebAPI Boilerplate是FullStackHero社区的一个用于快速搭建 Web API 的模板项目。 FullStackHero WebAPI Boilerplate v1.0.0版本和v1.0.1版本存在安全漏洞,该漏洞源于forgot password功能存在主机头注入漏洞,攻击者可以通过特制的请求泄露密码重置令牌。
CVSS Information
N/A
Vulnerability Type
N/A