ZeroHour

CVE-2022-23079

PoC
CVSS 2.0
6.8 medium
EPSS
1%p71
Published
()
Modified
Description

In motor-admin versions 0.0.1 through 0.2.56 are vulnerable to host header injection in the password reset functionality where malicious actor can send fake password reset email to arbitrary victim.

Vendors
getmotoradmin
Products
motor admin
Weakness
CWE-116
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P

In the news

No ingested article mentions this CVE yet.