Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A host header injection vulnerability in MEANStore 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This allows attackers to arbitrarily reset other users' passwords and compromise their accounts.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MEANStore 安全漏洞
Vulnerability Description
MEANStore是Michael Lynn个人开发者的一个电子商务/零售软件解决方案。 MEANStore 1.0版本存在安全漏洞,该漏洞源于对精心构造的密码重置链接的用户交互,允许攻击者获取密码重置令牌,从而任意重置其他用户的密码并危及其账户。
CVSS Information
N/A
Vulnerability Type
N/A