ZeroHour

CVE-2022-23068

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p47
Published
()
Modified
Description

ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail.

Vendors
tooljet
Products
tooljet
Weakness
CWE-74, CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.