Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-27506

Опубликовано: 06 мар. 2025
Источник: nvd
CVSS3: 5.4
CVSS3: 6.1
EPSS Низкий

Описание

NocoDB is software for building databases as spreadsheets. The API endpoint related to the password reset function is vulnerable to Reflected Cross-Site-Scripting. The endpoint /api/v1/db/auth/password/reset/:tokenId is vulnerable to Reflected Cross-Site-Scripting. The flaw occurs due to implementation of the client-side template engine ejs, specifically on file resetPassword.ts where the template is using the insecure function “<%-“, which is rendered by the function renderPasswordReset. This vulnerability is fixed in 0.258.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nocodb:nocodb:*:*:*:*:*:*:*:*
Версия до 0.258.0 (исключая)

EPSS

Процентиль: 39%
0.00174
Низкий

5.4 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
github
11 месяцев назад

NocoDB Vulnerable to Reflected Cross-Site Scripting on Reset Password Page

EPSS

Процентиль: 39%
0.00174
Низкий

5.4 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79