CVE-2022-23068

MEDIUM

Tooljet < 1.10.2 - Injection

Title source: rule
STIX 2.1

Description

ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail.

References (2)

Core 2

Scores

CVSS v3 5.4
EPSS 0.0021
EPSS Percentile 42.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-74 CWE-79
Status published
Products (1)
tooljet/tooljet 0.6.0 - 1.10.2
Published May 18, 2022
Tracked Since Feb 18, 2026