"TITLE":"motoradmin - host header Injection in the reset password functionality "
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"motor-admin",
"product":{
"product_data":[
{
"product_name":"motor-admin",
"version":{
"version_data":[
{
"version_value":"0.0.1",
"version_affected":">="
},
{
"version_value":"0.2.56",
"version_affected":"<="
}
]
}
}
]
}
}
]
}
},
"credit":[
{
"lang":"eng",
"value":"Mend Vulnerability Research Team (MVR)"
}
],
"data_format":"MITRE",
"data_type":"CVE",
"data_version":"4.0",
"description":{
"description_data":[
{
"lang":"eng",
"value":"In motor-admin versions 0.0.1 through 0.2.56 are vulnerable to host header injection in the password reset functionality where malicious actor can send fake password reset email to arbitrary victim."