6.8
CVE-2022-23079
- EPSS 1.28%
- Veröffentlicht 22.06.2022 13:15:08
- Zuletzt bearbeitet 21.11.2024 06:47:56
- Quelle vulnerabilitylab@mend.io
- CVE-Watchlists
- Unerledigt
motoradmin - host header Injection in the reset password functionality
In motor-admin versions 0.0.1 through 0.2.56 are vulnerable to host header injection in the password reset functionality where malicious actor can send fake password reset email to arbitrary victim.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Getmotoradmin ≫ Motor Admin Version >= 0.0.1 <= 0.2.56
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.28% | 0.663 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-116 Improper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
https://github.com/motor-admin/motor-admin/commit/a461b7507940a1fa062836daa89c82404fe3ecf9
https://www.mend.io/vulnerability-database/CVE-2022-23079