Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-7299

Опубликовано: 02 июн. 2026
Источник: nvd
CVSS3: 6.3
CVSS3: 5.4
EPSS Низкий

Описание

Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an authenticated Developer to inject persistent XSS by a malicious table or column names triggering arbitrary code execution in the sessions of other workspace members when they interact with the same datasource.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:appsmith:appsmith:*:*:*:*:*:*:*:*
Версия до 1.99 (исключая)

EPSS

Процентиль: 26%
0.00341
Низкий

6.3 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.3
github
2 месяца назад

Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an authenticated Developer to inject persistent XSS by a malicious table or column names triggering arbitrary code execution in the sessions of other workspace members when they interact with the same datasource.

EPSS

Процентиль: 26%
0.00341
Низкий

6.3 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79