CVE-2022-23079 Vulnerability Details
/
/
/
CVE-2022-23079 Metadata Quick Info
CVE Published: 22/06/2022 |
CVE Updated: 16/09/2024 |
CVE Year: 2022
Source: Mend |
Vendor: motor-admin |
Product: motor-admin
Status : PUBLISHED
CVE-2022-23079 Description
In motor-admin versions 0.0.1 through 0.2.56 are vulnerable to host header injection in the password reset functionality where malicious actor can send fake password reset email to arbitrary victim.
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID: CWE-116
CWE Name: CWE-116 Improper Encoding or Escaping of Output
Source: motor-admin
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).