SQL injection in NocoDB - CVE-2023-43794
Published: October 17, 2023 / Updated: April 27, 2026
NocoDB
nocodb
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to sql injection in the triggerList method in SqliteClient.ts when handling a crafted table_name parameter through the tableCreate endpoint. A remote privileged user can send a specially crafted request to disclose sensitive information.
The issue is a blind SQL injection that may require time-based payloads to infer query results from response timing.