NocoDB
cpe:2.3:a:nocodb:nocodb:*:*:*:*:*:*:*
- <= 0.301.2
A SQL injection vulnerability has been identified in NocoDB versions prior to 0.301.3. This issue allows authenticated users with the Creator role to inject arbitrary SQL through the DATEADD formula's unit parameter. The vulnerability arises because the unit parameter was directly interpolated into SQL queries without proper validation, leaving affected MySQL, PostgreSQL, and SQLite function mappings open to exploitation.
Exploitation of this vulnerability allows for SQL injection, enabling data exfiltration or modification within the connected database.
Users can upgrade to NocoDB version 0.301.3 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.