CVE-2022-23079 Vulnerability Details

  /     /     /  

CVE-2022-23079 Metadata Quick Info

CVE Published: 22/06/2022 | CVE Updated: 16/09/2024 | CVE Year: 2022
Source: Mend | Vendor: motor-admin | Product: motor-admin
Status : PUBLISHED

CVE-2022-23079 Description

In motor-admin versions 0.0.1 through 0.2.56 are vulnerable to host header injection in the password reset functionality where malicious actor can send fake password reset email to arbitrary victim.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-116
CWE Name: CWE-116 Improper Encoding or Escaping of Output
Source: motor-admin

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).