fourcube/security-advisories

fourcube/security-advisories

Releases0

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH

Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP request.

5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment Body component.