First published: Wed May 18 2022(Updated: )
ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail.
Credit: vulnerabilitylab@mend.io
Affected Software | Affected Version | How to fix |
---|---|---|
Tooljet Tooljet | >=0.6.0<=1.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23068 is a vulnerability in ToolJet versions v0.6.0 to v1.10.2 that allows an attacker to inject malicious code into the first name and last name fields when inviting a new user, which will be reflected in the invitational email.
CVE-2022-23068 has a severity score of 5.4, which is considered medium.
An attacker can exploit CVE-2022-23068 by injecting malicious code into the first name and last name fields while inviting a new user, which will be included in the invitational email.
ToolJet versions v0.6.0 to v1.10.2 are affected by CVE-2022-23068.
Yes, a fix for CVE-2022-23068 is available. It is recommended to upgrade to a version higher than v1.10.2 of ToolJet.