VYPR
High severity8.1NVD Advisory· Published Feb 29, 2024· Updated Jun 17, 2026

CVE-2024-26470

CVE-2024-26470

Description

A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackers to leak the password reset token via a crafted request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
FullStackHero.WebAPI.BoilerplateNuGet
>= 1.0.0, <= 1.0.1

Affected products

4

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.