Podatność CVE-2022-3422


Publikacja: 2022-10-07

Opis:
Account Takeover :: when see the info i can see the hash pass i can creaked it ............... Account Takeover :: when see the info i can see the forgot_password_token the hacker can send the request and changed the pass

Typ:

CWE-269

(Improper Privilege Management)

 Referencje:
https://huntr.dev/bounties/02da53ab-f613-4171-8766-96b31c671551
https://github.com/tooljet/tooljet/commit/7879d8a76000c014533a97a22bc276afe3ae3e54

Copyright 2024, cxsecurity.com

 

Back to Top