High severity8.1NVD Advisory· Published Feb 29, 2024· Updated Jun 17, 2026
CVE-2024-26470
CVE-2024-26470
Description
A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackers to leak the password reset token via a crafted request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
FullStackHero.WebAPI.BoilerplateNuGet | >= 1.0.0, <= 1.0.1 | — |
Affected products
4cpe:2.3:a:fullstackhero:.net_9_starter_kit:1.0.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:fullstackhero:.net_9_starter_kit:1.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:fullstackhero:.net_9_starter_kit:1.0.1:*:*:*:*:*:*:*
- FullStackHero/WebAPI Boilerplatedescription
Patches
Vulnerability mechanics
References
4- www.nuget.org/packages/FullStackHero.WebAPI.BoilerplatenvdExploitProductWEB
- github.com/advisories/GHSA-75x2-6h4m-h6mxghsaADVISORY
- github.com/dub-flow/vulnerability-research/tree/main/CVE-2024-26470nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-26470ghsaADVISORY
News mentions
0No linked articles in our index yet.