Vulnerabilities > CVE-2022-27978 - Improper Handling of Exceptional Conditions vulnerability in Tooljet 1.6
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
HIGH Availability impact
NONE Summary
Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP request.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |