PT-2022-4501 · Tooljet · Tooljet

Published

2022-08-22

·

Updated

2022-09-01

·

CVE-2022-3019

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ToolJet (affected versions not specified)
Description The issue is related to insufficient access control in the getComment() function of the ToolJet platform, which can be exploited by a remote attacker to elevate their privileges. This vulnerability allows an attacker to take over an account by exploiting the forgot password token, potentially by brute-forcing comment IDs, although this method is considered impractical due to the time it would take to find a valid ID.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

IDOR

Weakness Enumeration

Related Identifiers

BDU:2022-05368
CVE-2022-3019

Affected Products

Tooljet