motoradmin - host header Injection in the reset password functionality
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.4%
exploitation probability
1.4%top 29% of all CVEs
observed exploitation
nono source reports it
In motor-admin versions 0.0.1 through 0.2.56 are vulnerable to host header injection in the password reset functionality where malicious actor can send fake password reset email to arbitrary victim.
Affected products
motor-admin · motor-admin