Tooljet

Tooljet

15 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.73%
  • Veröffentlicht 29.08.2022 06:15:09
  • Zuletzt bearbeitet 21.11.2024 07:18:39

The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comment id's might also be an option but I wouldn't count on it, since it would take a long time to find a...

Exploit
  • EPSS 1.13%
  • Veröffentlicht 02.08.2022 17:15:10
  • Zuletzt bearbeitet 21.11.2024 07:01:24

Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0.

Exploit
  • EPSS 1.1%
  • Veröffentlicht 09.06.2022 17:15:09
  • Zuletzt bearbeitet 21.11.2024 07:00:12

Excessive Attack Surface in GitHub repository tooljet/tooljet prior to v1.16.0.

Exploit
  • EPSS 1.29%
  • Veröffentlicht 18.05.2022 14:15:08
  • Zuletzt bearbeitet 21.11.2024 06:47:55

ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If the user opens the invite link/signup link and then clicks on any external links within the page, it leaks the password set token...

Exploit
  • EPSS 0.61%
  • Veröffentlicht 18.05.2022 14:15:08
  • Zuletzt bearbeitet 21.11.2024 06:47:55

ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail.