CVE-2022-23068
Last modified
CVE-2022-23068 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail.. EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tooljet | Tooljet | >= 0.6.0, <= 1.10.2 |
References
- https://github.com/ToolJet/ToolJet/commit/431dc961cdfe4d26343d1c1c951ced778fbddb58Patch, Third Party Advisory
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-23068Exploit, Third Party Advisory
- https://github.com/ToolJet/ToolJet/commit/431dc961cdfe4d26343d1c1c951ced778fbddb58Patch, Third Party Advisory
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-23068Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-23068?
How severe is CVE-2022-23068?
How do I fix CVE-2022-23068?
Are you affected by CVE-2022-23068?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
