The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comment id's might also be an option but I wouldn't count on it, since it would take a long time to find a valid one).
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
https://huntr.dev/bounties/a610300b-ce3c-4995-8337-11942b3621bf | exploit third party advisory patch |
https://github.com/tooljet/tooljet/commit/45e0d3302d92df7d7f2d609c31cea71165600b79 | third party advisory patch |