PT-2024-31868 · Scheduler · Scheduler
Sourajeet Majumder
·
Published
2024-09-26
·
Updated
2024-10-01
·
CVE-2024-45982
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
scheduleR version 0.0.18
Description
A host header injection vulnerability allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This enables attackers to arbitrarily reset other users' passwords and compromise their accounts.
Recommendations
For scheduleR version 0.0.18, consider disabling the password reset functionality until a patch is available to prevent exploitation of the host header injection vulnerability. Restrict access to the password reset link to minimize the risk of account compromise.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Scheduler