Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wg7g-xr7v-hf69

Опубликовано: 13 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 8.3

Описание

Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint where user-supplied parameters are interpolated into JSON query templates without proper sanitization of JSON metacharacters. Attackers with query write permission can inject JSON structural characters to alter MongoDB queries, bypassing filters to read, modify, or delete arbitrary documents.

Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint where user-supplied parameters are interpolated into JSON query templates without proper sanitization of JSON metacharacters. Attackers with query write permission can inject JSON structural characters to alter MongoDB queries, bypassing filters to read, modify, or delete arbitrary documents.

EPSS

Процентиль: 22%
0.0029
Низкий

8.7 High

CVSS4

8.3 High

CVSS3

Дефекты

CWE-943

Связанные уязвимости

CVSS3: 8.3
nvd
6 дней назад

Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint where user-supplied parameters are interpolated into JSON query templates without proper sanitization of JSON metacharacters. Attackers with query write permission can inject JSON structural characters to alter MongoDB queries, bypassing filters to read, modify, or delete arbitrary documents.

EPSS

Процентиль: 22%
0.0029
Низкий

8.7 High

CVSS4

8.3 High

CVSS3

Дефекты

CWE-943