Baserow 2.3.3 版本中的 公式函数存在 SQL 注入漏洞。一个拥有低权限的已认证用户,若能创建或修改公式字段,可以传入一个未被文档说明的第四个参数,该参数会被当作 SQL 模板,并直接拼接(插值)到 PostgreSQL 表达式中。 当 Baserow 重新计算公式字段值时,会执行该存在漏洞的表达式。由于生成的 SQL 通过 Baserow 的数据库连接执行,注入的 SQL 将以 Baserow 所使用的 PostgreSQL 角色的权限运行,而非已认证应用用户的权限。 此问题影响 Baserow 版本
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet