Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c4fh-wf5v-23wx

Опубликовано: 19 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If the user opens the invite link/signup link and then clicks on any external links within the page, it leaks the password set token/signup token in the referer header. Using these tokens the attacker can access the user’s account.

ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If the user opens the invite link/signup link and then clicks on any external links within the page, it leaks the password set token/signup token in the referer header. Using these tokens the attacker can access the user’s account.

EPSS

Процентиль: 60%
0.00397
Низкий

8.8 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 8.8
nvd
больше 3 лет назад

ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If the user opens the invite link/signup link and then clicks on any external links within the page, it leaks the password set token/signup token in the referer header. Using these tokens the attacker can access the user’s account.

EPSS

Процентиль: 60%
0.00397
Низкий

8.8 High

CVSS3

Дефекты

CWE-200