CVE-2024-48322
HIGHRun.codes <= 1.5.2 - Time-of-check Time-of-use Race Condition in UsersController.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-48322. PoCs published by trqt.
AI-analyzed exploit summary This PoC exploits an email-based password recovery vulnerability in Run.codes by sending multiple recovery requests via HTTP/2, potentially leaking the victim's password reset link to the attacker's email. The script automates the process by alternating between attacker and victim emails in a loop.
Description
UsersController.php in Run.codes 1.5.2 and older has a reset password race condition vulnerability.
Exploits (1)
This PoC exploits an email-based password recovery vulnerability in Run.codes by sending multiple recovery requests via HTTP/2, potentially leaking the victim's password reset link to the attacker's email. The script automates the process by alternating between attacker and victim emails in a loop.
References (4)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H