WRITEUP

WRITEUP
Exploit for CVE-2024-45980 - MEANStore 1.0 - Host Header Injection
AI Analysis

The repository contains a detailed technical writeup of a host header injection vulnerability in the forgot password functionality of MEANStore 1.0. It explains how an attacker can manipulate the host header to send password reset links to an attacker-controlled server, leading to token leakage and potential account takeover.

Attack Type
info_leak
Complexity
trivial
Reliability
reliable
MITRE ATT&CK
T1189 - Drive-by Compromise
Loading exploit code...
Download ZIP Password: eip
Vulnerability
CVE-2024-45980
MEANStore 1.0 - Host Header Injection
HIGH
CVSS 8.8