PT-2023-12928 · Tooljet · Tooljet
Chris Grieger
·
Published
2023-04-26
·
Updated
2023-05-04
·
CVE-2022-27978
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Tooljet version 1.6
Description
The issue arises from the improper handling of missing values in the API, allowing attackers to send a crafted HTTP request to arbitrarily reset passwords.
Recommendations
For Tooljet version 1.6, consider restricting access to the password reset functionality until a proper fix is implemented to handle missing values in the API. As a temporary workaround, avoid using the password reset feature via the API to minimize the risk of exploitation.
Exploit
Fix
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tooljet