6.8

CVE-2022-23079

Exploit

motoradmin - host header Injection in the reset password functionality

In motor-admin versions 0.0.1 through 0.2.56 are vulnerable to host header injection in the password reset functionality where malicious actor can send fake password reset email to arbitrary victim.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GetmotoradminMotor Admin Version >= 0.0.1 <= 0.2.56
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.28% 0.663
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-116 Improper Encoding or Escaping of Output

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

https://github.com/motor-admin/motor-admin/commit/a461b7507940a1fa062836daa89c82404fe3ecf9
Patch
Third Party Advisory
https://www.mend.io/vulnerability-database/CVE-2022-23079
Third Party Advisory
Exploit