CVE-2022-23068: ToolJet - HTML Injection in Invite New User
ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-23068?
CVE-2022-23068 is a vulnerability in ToolJet versions v0.6.0 to v1.10.2 that allows an attacker to inject malicious code into the first name and last name fields when inviting a new user, which will be reflected in the invitational email.
How severe is CVE-2022-23068?
CVE-2022-23068 has a severity score of 5.4, which is considered medium.
How can an attacker exploit CVE-2022-23068?
An attacker can exploit CVE-2022-23068 by injecting malicious code into the first name and last name fields while inviting a new user, which will be included in the invitational email.
Which versions of ToolJet are affected by CVE-2022-23068?
ToolJet versions v0.6.0 to v1.10.2 are affected by CVE-2022-23068.
Is there a fix for CVE-2022-23068?
Yes, a fix for CVE-2022-23068 is available. It is recommended to upgrade to a version higher than v1.10.2 of ToolJet.