SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-23068

ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail.

MEDIUM 5.4EPSS 0.61%

Does this matter?

Lower severity and a low EPSS score (0.61%). Track it; it rarely justifies an emergency change on its own.

Description

ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
0.61% probability · 47th percentile
CISA KEV
Not listed
Weakness
CWE-74, CWE-79
Affected
tooljet/tooljet
Source
vulnerabilitylab@mend.io

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.