PT-2022-21994 · Togglee · Togglee

Kanekotic

·

Published

2022-06-24

·

Updated

2022-07-06

·

CVE-2022-34060

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Togglee version v0.0.8
Description The Togglee package was discovered to contain a code execution backdoor, allowing attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
Recommendations For version v0.0.8, consider removing or avoiding the use of the Togglee package until a patched version is available. As a temporary workaround, restrict access to sensitive information and digital currency keys to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-34060

Affected Products

Togglee