Home/Product/tooljet
Product

tooljet

10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2022-27979
all versions
A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a craft
5.4MEDIUM
CVE-2022-27978
all versions
Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted H
7.5HIGH
CVE-2022-4111
< 1.27.0
Unrestricted file size limit can lead to DoS in tooljet/tooljet <1.27 by allowing a logged in attacker to upload profile pictures
6.5MEDIUM
CVE-2022-3422
< 1.26.1
Account Takeover :: when see the info i can see the hash pass i can creaked it ............... Account Takeover :: when see the in
7.5HIGH
CVE-2022-3348
< 2022-09-11
Just like in the previous report, an attacker could steal the account of different users. But in this case, it's a little bit more
4.9MEDIUM
CVE-2022-3019
< 1.23.0
The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see
8.8HIGH
CVE-2022-2631
< 1.19.0
Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0.
8.8HIGH
CVE-2022-2037
< 1.16.0
Excessive Attack Surface in GitHub repository tooljet/tooljet prior to v1.16.0.
8.0HIGH
CVE-2022-23068
>= 0.6.0 and <= 1.10.2
ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first n
5.4MEDIUM
CVE-2022-23067
>= 0.5.0 and <= 1.2.2
ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If the user
8.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin