SQLBot through 1.10.1 Improper Access Control via Dashboard Update
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.1epss 0.2%
probabilidad de explotación
0.2%top 84% de las CVE
explotación observada
noninguna fuente lo reporta
SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards. Attackers can supply arbitrary dashboard IDs to rename dashboards and overwrite component data, canvas styles, and view information belonging to other workspace members.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Productos afectados
dataease · SQLBotReferencias
https://github.com/dataease/SQLBothttps://github.com/dataease/SQLBot/blob/v1.10.1/backend/apps/dashboard/crud/dashboard_service.pyhttps://github.com/dataease/SQLBot/blob/v1.10.1/backend/apps/system/schemas/permission.pyhttps://github.com/dataease/SQLBot/commit/fccdd29421dfc32d3a552ab29b2554974e1ebc4chttps://github.com/dataease/SQLBot/issues/1377https://www.vulncheck.com/advisories/sqlbot-through-1.10.1-improper-access-control-via-dashboard-update