PT-2022-15826 · Tooljet · Tooljet

Published

2022-05-18

·

Updated

2022-05-26

·

CVE-2022-23067

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ToolJet versions v0.5.0 to v1.2.2
Description The issue allows for token leakage via the Referer header, leading to account takeover. When a user opens an invite link or signup link and then clicks on external links within the page, the password set token or signup token is leaked in the Referer header. An attacker can use these tokens to access the user's account.
Recommendations For ToolJet versions v0.5.0 to v1.2.2, consider restricting access to external links within the invite link/signup link page until a fix is available. As a temporary workaround, avoid using the invite link/signup link feature to minimize the risk of token leakage.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23067

Affected Products

Tooljet