Vulnerabilities (CVE)

Filtered by vendor Tooljet Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-2037 1 Tooljet 1 Tooljet 2022-06-15 6.0 MEDIUM 8.0 HIGH
Excessive Attack Surface in GitHub repository tooljet/tooljet prior to v1.16.0.
CVE-2022-23067 1 Tooljet 1 Tooljet 2022-05-26 6.8 MEDIUM 8.8 HIGH
ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If the user opens the invite link/signup link and then clicks on any external links within the page, it leaks the password set token/signup token in the referer header. Using these tokens the attacker can access the user’s account.