ToolJet - HTML Injection in Invite New User
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 5.4epss 0.6%
probabilidade de exploração
0.6%top 55% das CVEs
exploração observada
nãonenhuma fonte reporta
ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Produtos afetados
ToolJet · ToolJet