
XSS via Host Header injection and Steal Password Reset Token of another user
CVE-2022-24181 and CVE-2022-26616. both are probably same
XSS via Host Header injection and Steal Password Reset Token of another user Step to reproduce:
Google Dork to find This vulnerability intitle:ojs This vulnerability in PKP vendor software Open-journal-system version 2.4.8 to 3.3.8 all are vulnerable to xss via Host Header injection and steal password reset token vulnerability