CVE-2023-50718
NocoDB is software for building databases as spreadsheets. Prior to version 0.202.10, an authenticated attacker with cre
NocoDB is software for building databases as spreadsheets. Prior to version 0.202.10, an authenticated attacker with create access could conduct a SQL Injection attack on MySQL DB using unescaped table_name. This vulnerability may result in leakage of sensitive data in the database.
Version 0.202.10 contains a patch for the issue.
MEDIUM · CVSS 6.5
EPSS 0.00231
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0