CVE-2022-27978
EUVD-2022-3246426.04.2023, 16:15
Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP request.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| tooljet | tooljet | 1.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration