CVE-2023-39655
CVSS 3.1 Score 9.6 of 10 (high)
Details
Published Jan 3, 2024
Updated: Jan 9, 2024
CWE ID 74
Summary
CVE-2023-39655 is a host header injection vulnerability affecting the NPM package @perfood/couch-auth versions below 0.20.1. Malicious actors can exploit this flaw by sending a crafted host header in a forgot password request. The vulnerability enables attackers to redirect password reset links to their own servers, potentially leading to the leakage of password reset tokens. This could allow unauthorized individuals to reset other users' passwords and gain unauthorized access to their accounts.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Perfood