Host Header Injection Vulnerability in Perfood's Couch-Auth Package
CVE-2024-57177
7.3HIGH
What is CVE-2024-57177?
A host header injection vulnerability in Perfood's Couch-Auth NPM package allows attackers to manipulate the host header in an email change confirmation request. This vulnerability can lead to server-side template injection (SSTI), enabling adversaries to execute limited commands or disclose sensitive server-side information by sending crafted requests.