PT-2023-12928 · Tooljet · Tooljet

Chris Grieger

·

Published

2023-04-26

·

Updated

2023-05-04

·

CVE-2022-27978

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Tooljet version 1.6
Description The issue arises from the improper handling of missing values in the API, allowing attackers to send a crafted HTTP request to arbitrarily reset passwords.
Recommendations For Tooljet version 1.6, consider restricting access to the password reset functionality until a proper fix is implemented to handle missing values in the API. As a temporary workaround, avoid using the password reset feature via the API to minimize the risk of exploitation.

Exploit

Fix

Improper Handling of Exceptional Conditions

Weakness Enumeration

Related Identifiers

CVE-2022-27978

Affected Products

Tooljet