CVE-2024-45981
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-45981 is a newly identified vulnerability affecting the BookReviewLibrary 1.0 application. This issue is classified as a host header injection vulnerability, which allows attackers to manipulate header information sent to the server. By crafting a malicious password reset link, adversaries can trick users into resetting their accounts with a token obtained through this vulnerability. Successful exploitation could lead to unauthorized password resets and potential account takeover. Users are strongly advised to update their software to a patched version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.