NocoDB
cpe:2.3:a:nocodb:nocodb:*:*:*:*:*:*:*
- <= 0.301.2
A stored cross-site scripting (XSS) vulnerability has been identified in NocoDB versions prior to 0.301.3. The issue resides in the Formula virtual cell, where results containing 'URI::()' patterns are rendered using 'v-html' without proper sanitization. This oversight allows injected HTML to execute. A user with a Creator role can exploit this by crafting a formula that includes malicious scripts, which are then executed for all viewers of the table.
Exploitation of this vulnerability could lead to cross-site scripting, allowing for the execution of scripts in the context of the user viewing the table, potentially leading to credential theft.
Users can upgrade to NocoDB version 0.301.3 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.