Security Advisory

CVE-2022-27978

7.5
HIGH

Vulnerability Description

Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP request.
Published Date April 26, 2023
Official Source NIST NVD Advisory