SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-23079

In motor-admin versions 0.0.1 through 0.2.56 are vulnerable to host header injection in the password reset functionality where malicious actor can send fake password reset email to arbitrary victim.

MEDIUM 6.8EPSS 1.38%

Does this matter?

Lower severity and a low EPSS score (1.38%). Track it; it rarely justifies an emergency change on its own.

Description

In motor-admin versions 0.0.1 through 0.2.56 are vulnerable to host header injection in the password reset functionality where malicious actor can send fake password reset email to arbitrary victim.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
1.38% probability · 71th percentile
CISA KEV
Not listed
Weakness
CWE-116
Affected
getmotoradmin/motor admin
Source
vulnerabilitylab@mend.io

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.