在 Budibase 3.45.0 版本之前, 组件在 中构建 MySQL 和 MSSQL 的列重命名 DDL(数据定义语言)语句时,存在直接插值漏洞。具体而言,标识符被直接插入到原始查询字符串中(MySQL 使用反引号包裹,MSSQL 使用单引号包装的 字面量),而未能应用项目内置的 / 安全辅助函数进行正确转义。 具备连接 MySQL 或 MSSQL 数据源 DDL 权限的攻击者,可以创建一个列名中包含特殊字符的列:对于 MySQL,列名可包含反引号及额外 SQL 代码;对于 MSSQL,列名可包含单引号及额外
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100682 | 8.8 HIGH | Budibase Server before 3.45.0 Arbitrary File Write via ZIP Symlink |
| CVE-2026-100686 | 8.1 HIGH | Budibase before 3.45.0 Cross-Workspace Privilege Escalation via POST /api/global/groups/:g |
| CVE-2026-100684 | 8.1 HIGH | Budibase Server 3.41.0 before 3.45.0 Authentication Bypass via OIDC |
| CVE-2026-100680 | 8.1 HIGH | Budibase before 3.45.0 Arbitrary Local File Read via OpenAPI Import |
| CVE-2026-100685 | 7.7 HIGH | Budibase before 3.45.0 Information Disclosure via Chat Links |
| CVE-2026-100688 | 6.5 MEDIUM | Budibase server before 3.45.0 Cross-Tenant Information Disclosure |
| CVE-2026-100687 | 5.5 MEDIUM | Budibase Server before 3.45.0 Credential Exposure via External Table Broadcast |
| CVE-2026-100681 | 5.4 MEDIUM | Budibase before 3.45.0 SSRF and OAuth Token Exfiltration via Teams Webhook |
No comments yet