CVE-2022-23079

motor-admin <0.2.56 - Host Header Injection

Title source: llm
STIX 2.1

Description

In motor-admin versions 0.0.1 through 0.2.56 are vulnerable to host header injection in the password reset functionality where malicious actor can send fake password reset email to arbitrary victim.

References (2)

Core 2

Scores

EPSS 0.0132
EPSS Percentile 67.9%

Details

CWE
CWE-116
Status published
Products (1)
getmotoradmin/motor_admin 0.0.1 - 0.2.56
Published Jun 22, 2022
Tracked Since Feb 18, 2026