CVE-2022-23079

motor-admin <0.2.56 - Host Header Injection

Title source: llm
STIX 2.1

Description

In motor-admin versions 0.0.1 through 0.2.56 are vulnerable to host header injection in the password reset functionality where malicious actor can send fake password reset email to arbitrary victim.

References (2)

Core 2

Scores

EPSS 0.0115
EPSS Percentile 62.6%

Details

CWE
CWE-116
Status published
Products (1)
getmotoradmin/motor_admin 0.0.1 - 0.2.56
Published Jun 22, 2022
Tracked Since Feb 18, 2026