@perfood/couch-auth
cpe:2.3:a:perfood:couchauth:*:*:*:*:node.js:*:*
- <= 0.26.0
A host header injection vulnerability has been identified in the mailer component of @perfood/couch-auth, specifically in version 0.26.0. This vulnerability allows attackers to spoof the HTTP Host header, enabling them to obtain password reset tokens or email confirmation links. Such actions could lead to unauthorized account access.
Exploitation of this vulnerability could result in unauthorized account access through account takeover.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.