CVE-2025-53373 Natours has a 1 Click Account take over on reset password via Host Header injection
Discription

image
Natours is a Tour Booking API. The attacker can easily take over any victim account by injecting an attacker-controlled server domain in the Host header when requesting the /forgetpassword endpoint. This vulnerability is fixed with commit…Read More

Back to Main

Subscribe for the latest news: