Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-73618

Опубликовано: 13 авг. 2026
Источник: nvd
CVSS3: 8.3
EPSS Низкий

Описание

Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint where user-supplied parameters are interpolated into JSON query templates without proper sanitization of JSON metacharacters. Attackers with query write permission can inject JSON structural characters to alter MongoDB queries, bypassing filters to read, modify, or delete arbitrary documents.

EPSS

Процентиль: 22%
0.0029
Низкий

8.3 High

CVSS3

Дефекты

CWE-943

Связанные уязвимости

CVSS3: 8.3
github
6 дней назад

Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint where user-supplied parameters are interpolated into JSON query templates without proper sanitization of JSON metacharacters. Attackers with query write permission can inject JSON structural characters to alter MongoDB queries, bypassing filters to read, modify, or delete arbitrary documents.

EPSS

Процентиль: 22%
0.0029
Низкий

8.3 High

CVSS3

Дефекты

CWE-943