Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6j63-xfwq-f8vj

Опубликовано: 02 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an authenticated Developer to inject persistent XSS by a malicious table or column names triggering arbitrary code execution in the sessions of other workspace members when they interact with the same datasource.

Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an authenticated Developer to inject persistent XSS by a malicious table or column names triggering arbitrary code execution in the sessions of other workspace members when they interact with the same datasource.

EPSS

Процентиль: 27%
0.00341
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.3
nvd
2 месяца назад

Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an authenticated Developer to inject persistent XSS by a malicious table or column names triggering arbitrary code execution in the sessions of other workspace members when they interact with the same datasource.

EPSS

Процентиль: 27%
0.00341
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-79