CVE-2022-23068

MEDIUM

ToolJet 0.6.0-1.10.2 - HTML Injection via User Invitation Name Fields

Title source: llm
STIX 2.1

Description

ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail.

References (2)

Core 2

Scores

CVSS v3 5.4
EPSS 0.0058
EPSS Percentile 43.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-74 CWE-79
Status published
Products (1)
tooljet/tooljet 0.6.0 - 1.10.2
Published May 18, 2022
Tracked Since Feb 18, 2026