webPromedium

Lab 188 — PulseBoard — Host Header Injection in Password Reset

hackadvisor

Task: PulseBoard team analytics platform with password reset functionality. Solution: Host header injection via X-Forwarded-Host leaks password reset token in debug response, enabling admin account takeover.

$ ls tags/ techniques/
privilege_escalationhost_header_injectionpassword_reset_poisoning

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups