PT-2022-15827 · Tooljet · Tooljet

CVE-2022-23068

·

Published

2022-05-18

·

Updated

2023-06-27

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ToolJet versions v0.6.0 to v1.10.2
Description The issue allows an attacker to inject malicious code inside the first name and last name fields while inviting a new user, which will be reflected in the invitational e-mail. This is an HTML injection issue.
Recommendations For ToolJet versions v0.6.0 to v1.10.2, consider restricting the input for the first name and last name fields to prevent HTML injection until a patch is available. As a temporary workaround, validate and sanitize user input in these fields to minimize the risk of exploitation.

Exploit

Fix

XSS

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23068

Affected Products

Tooljet