CVE-2022-3422: Improper Privilege Management in tooljet/tooljet
Published Oct 7, 2022
·Updated
Account Takeover :: when see the info i can see the hash pass i can creaked it ............... Account Takeover :: when see the info i can see the forgotpasswordtoken the hacker can send the request and changed the pass
Affected Software
1 affected component
Tooljet tooljet<1.26.1
Remediation
Event History
Oct 7, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-3422?
CVE-2022-3422 is rated as a critical vulnerability due to its potential for Account Takeover.
2
How do I fix CVE-2022-3422?
To fix CVE-2022-3422, upgrade Tooljet to version 1.26.1 or later.
3
What software is affected by CVE-2022-3422?
CVE-2022-3422 affects all versions of Tooljet prior to 1.26.1.
4
What type of attack does CVE-2022-3422 enable?
CVE-2022-3422 enables an attacker to perform an Account Takeover through compromised tokens.
5
Can CVE-2022-3422 be exploited remotely?
Yes, CVE-2022-3422 can be exploited remotely, making it a significant security risk.