6.8
CVE-2022-23079
- EPSS 0.3%
- Veröffentlicht 22.06.2022 13:15:08
- Zuletzt bearbeitet 21.11.2024 06:47:56
- Quelle vulnerabilitylab@mend.io
- CVE-Watchlists
- Unerledigt
In motor-admin versions 0.0.1 through 0.2.56 are vulnerable to host header injection in the password reset functionality where malicious actor can send fake password reset email to arbitrary victim.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Getmotoradmin ≫ Motor Admin Version >= 0.0.1 <= 0.2.56
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.525 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-116 Improper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.