NA

CVE-2022-27979

Published: 26/04/2023 Updated: 04/05/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment Body component.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tooljet tooljet 1.6.0

Github Repositories

Security advisories, writeups and articles Security Advisories CVE Title Date CVE-2022-27978 Unauthorized password manipulation in ToolJet Server 2022/03/20 CVE-2022-27979 Persistent XSS in ToolJet Server 2022/03/20