CVE-2025-53373

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-53373
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-53373.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-53373
Aliases
  • GHSA-8gmw-7p75-58qv
Published
2025-07-07T16:15:24Z
Modified
2025-07-08T16:18:34Z
Summary
[none]
Details

Natours is a Tour Booking API. The attacker can easily take over any victim account by injecting an attacker-controlled server domain in the Host header when requesting the /forgetpassword endpoint. This vulnerability is fixed with commit 7401793a8d9ed0f0c250c4e0ee2815d685d7a70b.

References

Affected packages

Git / github.com/ahmed-elgaml11/natours

Affected ranges

Type
GIT
Repo
https://github.com/ahmed-elgaml11/natours
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed