{"id":"CVE-2022-23079","summary":"motoradmin - host header Injection in the reset password functionality","details":"In motor-admin versions 0.0.1 through 0.2.56 are vulnerable to host header injection in the password reset functionality where malicious actor can send fake password reset email to arbitrary victim.","modified":"2026-08-12T03:51:28.180297587Z","published":"2022-06-22T13:05:10.447Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23079.json","cna_assigner":"Mend","cwe_ids":["CWE-116"]},"references":[{"type":"WEB","url":"https://www.mend.io/vulnerability-database/CVE-2022-23079"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23079.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23079"},{"type":"FIX","url":"https://github.com/motor-admin/motor-admin/commit/a461b7507940a1fa062836daa89c82404fe3ecf9"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/motor-admin/motor-admin","events":[{"introduced":"7ac753980eaf986a2b1461d27fb3605e05ee2398"},{"fixed":"a461b7507940a1fa062836daa89c82404fe3ecf9"}],"database_specific":{"cpe":"cpe:2.3:a:getmotoradmin:motor_admin:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.0.1"},{"last_affected":"0.2.56"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["0.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23079.json"}}],"schema_version":"1.9.0"}