In motor-admin versions 0.0.1 through 0.2.56 are...
High severity
Unreviewed
Published
Jun 23, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Jun 22, 2022
Published to the GitHub Advisory Database
Jun 23, 2022
Last updated
Jan 27, 2023
In motor-admin versions 0.0.1 through 0.2.56 are vulnerable to host header injection in the password reset functionality where malicious actor can send fake password reset email to arbitrary victim.
References