An incident handler is reviewing WAF logs and notices repeated HTTP requests to a web application where the 'Host' header contains an attacker-controlled domain, while the request line targets the legitimate application server. The application uses the Host header to construct password-reset links emailed to users. Which web application injection attack class BEST describes this activity?
The attacker manipulates the Host header so the application embeds the attacker's domain into the password-reset URL. When a victim clicks the link, the reset token is sent to the attacker-controlled server. This matches the observed traffic and the application's behavior of using the Host header for link generation.
Why this answer
The attacker exploits the application's trust in the Host header to generate password-reset links. By setting the Host header to an attacker-controlled domain, the reset email contains a link pointing to that domain, allowing token theft. This is a classic Host header injection attack, distinct from CSRF, SSRF, and response splitting.
Exam trap
The trap here is assuming that any manipulation of the Host header automatically indicates SSRF or CSRF, when in fact the specific impact depends on how the application uses that header.