SQL injection in NocoDB - CVE-2023-50718
Published: May 13, 2024 / Updated: April 27, 2026
NocoDB
nocodb
Description
The vulnerability allows a remote user to disclose sensitive information and modify data.
The vulnerability exists due to improper neutralization of special elements used in an sql command in VitessClient.ts when processing a user-supplied table name for MySQL queries. A remote privileged user can send a specially crafted table name to disclose sensitive information and modify data.
Create access is required for exploitation.