CVE-2024-42914 - ArrowCMS Host Header Injection
<strong>CVE ID : </strong>CVE-2024-42914
<br>
<strong>Published : </strong> Aug. 23, 2024, 7:15 p.m. | 9 hours, 36 minutes ago
<br>
<strong>Description : </strong>A host header injection vulnerability exists in the forgot password functionality of ArrowCMS version 1.0.0. By sending a specially crafted host header in the forgot password request, it is possible to send password reset links to users which, once clicked, lead to an attacker-controlled server and thus leak the password reset token. This may allow an attacker to reset other users' passwords.
<br>
<strong>Severity:</strong> 0.0 | NA
<br>
Visit the link for more details, such as CVSS details, affected products, timeline, and more...