CVE-2022-27979: XSS
Published Apr 26, 2023
·Updated
A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment Body component.
Affected Software
1 affected component
Tooljet tooljet=1.6.0
Event History
Apr 26, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this XSS vulnerability in ToolJet v1.6.0?
The vulnerability ID for this XSS vulnerability in ToolJet v1.6.0 is CVE-2022-27979.
2
What is the severity of CVE-2022-27979?
The severity of CVE-2022-27979 is medium (5.4).
3
How does the XSS vulnerability in ToolJet v1.6.0 allow attackers to execute arbitrary web scripts or HTML?
The XSS vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML by injecting a crafted payload into the Comment Body component.
4
Which software version is affected by this XSS vulnerability?
The ToolJet version 1.6.0 is affected by this XSS vulnerability.
5
Are there any references available for this XSS vulnerability in ToolJet v1.6.0?
Yes, you can find references for this XSS vulnerability in ToolJet v1.6.0 at http://tooljet.com and https://github.com/fourcube/security-advisories/blob/main/security-advisories/20220321-tooljet-xss.md.