Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2wqm-v6p6-8mqx

Опубликовано: 19 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail.

ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail.

EPSS

Процентиль: 43%
0.00206
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-74
CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 3 лет назад

ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail.

EPSS

Процентиль: 43%
0.00206
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-74
CWE-79