CVE-2024-45981

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Sep 26, 2024
Updated: Sep 30, 2024
CWE ID 601

Summary

CVE-2024-45981 is a newly identified vulnerability affecting the BookReviewLibrary 1.0 application. This issue is classified as a host header injection vulnerability, which allows attackers to manipulate header information sent to the server. By crafting a malicious password reset link, adversaries can trick users into resetting their accounts with a token obtained through this vulnerability. Successful exploitation could lead to unauthorized password resets and potential account takeover. Users are strongly advised to update their software to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share