CVE-2024-6056
CVSS 3.1 Score 3.7 of 10 (low)
Details
Published Jun 17, 2024
Updated: Jun 20, 2024
CWE ID 204
Summary
CVE-2024-6656: A high-severity vulnerability was identified in nasirkhan's Laravel Starter up to version 11.8.0. This issue, rated as problematic, affects the Password Reset Handler's /forgot-password file. Manipulation of the Email argument can lead to observable response discrepancies, potentially allowing remote attackers to exploit this complex and difficult-to-exploit vulnerability, which has been publicly disclosed and may be actively used. The vendor was contacted about this disclosure but did not respond. (VDB-268784)
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.