PT-2023-12928 · Tooljet · Tooljet
Chris Grieger
·
Publicado
2023-04-26
·
Atualizado
2023-05-04
·
CVE-2022-27978
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Tooljet version 1.6
Description
The issue arises from the improper handling of missing values in the API, allowing attackers to send a crafted HTTP request to arbitrarily reset passwords.
Recommendations
For Tooljet version 1.6, consider restricting access to the password reset functionality until a proper fix is implemented to handle missing values in the API. As a temporary workaround, avoid using the password reset feature via the API to minimize the risk of exploitation.
Exploit
Correção
Improper Handling of Exceptional Conditions
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Tooljet