漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Natours has a 1 Click Account take over on reset password via Host Header injection
Vulnerability Description
Natours is a Tour Booking API. The attacker can easily take over any victim account by injecting an attacker-controlled server domain in the Host header when requesting the /forgetpassword endpoint. This vulnerability is fixed with commit 7401793a8d9ed0f0c250c4e0ee2815d685d7a70b.
CVSS Information
N/A
Vulnerability Type
忘记口令恢复机制弱
Vulnerability Title
Natours 授权问题漏洞
Vulnerability Description
Natours是Ahmed Emad个人开发者的一个旅游预订API。 Natours存在授权问题漏洞,该漏洞源于Host标头注入,可能导致账户接管。
CVSS Information
N/A
Vulnerability Type
N/A