ZeroHour

CVE-2024-45522

CVSS 3.1
9.8 critical
EPSS
<1%p44
Published
()
Modified
Description

Linen before cd37c3e does not verify that the domain is linen.dev or www.linen.dev when resetting a password. This occurs in create in apps/web/pages/api/forgot-password/index.ts.

Vendors
linen
Products
linen
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.