Логотип exploitDog
bind:CVE-2022-3019
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-3019

Количество 3

Количество 3

nvd логотип

CVE-2022-3019

больше 3 лет назад

The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comment id's might also be an option but I wouldn't count on it, since it would take a long time to find a valid one).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-w4fh-p39j-749c

больше 3 лет назад

The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comment id's might also be an option but I wouldn't count on it, since it would take a long time to find a valid one).

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2022-05368

больше 3 лет назад

Уязвимость функции getComment() платформы для создания приложений ToolJet, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-3019

The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comment id's might also be an option but I wouldn't count on it, since it would take a long time to find a valid one).

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-w4fh-p39j-749c

The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comment id's might also be an option but I wouldn't count on it, since it would take a long time to find a valid one).

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2022-05368

Уязвимость функции getComment() платформы для создания приложений ToolJet, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу