Логотип exploitDog
bind:CVE-2023-50717
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-50717

Количество 2

Количество 2

nvd логотип

CVE-2023-50717

больше 1 года назад

NocoDB is software for building databases as spreadsheets. Starting in verson 0.202.6 and prior to version 0.202.10, an attacker can upload a html file with malicious content. If user tries to open that file in browser malicious scripts can be executed leading stored cross-site scripting attack. This allows remote attacker to execute JavaScript code in the context of the user accessing the vector. An attacker could have used this vulnerability to execute requests in the name of a logged-in user or potentially collect information about the attacked user by displaying a malicious form. Version 0.202.10 contains a patch for the issue.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-qg73-g3cf-vhhh

больше 1 года назад

NocoDB Allows Preview of Files with Dangerous Content

CVSS3: 5.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-50717

NocoDB is software for building databases as spreadsheets. Starting in verson 0.202.6 and prior to version 0.202.10, an attacker can upload a html file with malicious content. If user tries to open that file in browser malicious scripts can be executed leading stored cross-site scripting attack. This allows remote attacker to execute JavaScript code in the context of the user accessing the vector. An attacker could have used this vulnerability to execute requests in the name of a logged-in user or potentially collect information about the attacked user by displaying a malicious form. Version 0.202.10 contains a patch for the issue.

CVSS3: 5.7
1%
Низкий
больше 1 года назад
github логотип
GHSA-qg73-g3cf-vhhh

NocoDB Allows Preview of Files with Dangerous Content

CVSS3: 5.7
1%
Низкий
больше 1 года назад

Уязвимостей на страницу