CVE-2023-50718

NocoDB is software for building databases as spreadsheets. Prior to version 0.202.10, an authenticated attacker with create access could conduct a SQL Injection attack on MySQL DB using unescaped `table_name`. This vulnerability may result in leakage of sensitive data in the database. Version 0.202.10 contains a patch for the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nocodb:nocodb:*:*:*:*:*:*:*:*

History

26 Aug 2025, 18:52

Type Values Removed Values Added
CPE cpe:2.3:a:xgenecloud:nocodb:*:*:*:*:*:*:*:* cpe:2.3:a:nocodb:nocodb:*:*:*:*:*:*:*:*
First Time Nocodb
Nocodb nocodb

21 Aug 2025, 17:02

Type Values Removed Values Added
First Time Xgenecloud
Xgenecloud nocodb
CPE cpe:2.3:a:xgenecloud:nocodb:*:*:*:*:*:*:*:*
References () https://github.com/nocodb/nocodb/security/advisories/GHSA-8fxg-mr34-jqr8 - () https://github.com/nocodb/nocodb/security/advisories/GHSA-8fxg-mr34-jqr8 - Exploit, Vendor Advisory

21 Nov 2024, 08:37

Type Values Removed Values Added
References () https://github.com/nocodb/nocodb/security/advisories/GHSA-8fxg-mr34-jqr8 - () https://github.com/nocodb/nocodb/security/advisories/GHSA-8fxg-mr34-jqr8 -
Summary
  • (es) NocoDB es un software para crear bases de datos como hojas de cálculo. Antes de la versión 0.202.10, un atacante autenticado con acceso de creación podía realizar un ataque de inyección SQL en una base de datos MySQL utilizando `table_name` sin escape. Esta vulnerabilidad puede provocar la fuga de datos confidenciales en la base de datos. La versión 0.202.10 contiene un parche para el problema.

14 May 2024, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 14:17

Updated : 2025-08-26 18:52


NVD link : CVE-2023-50718

Mitre link : CVE-2023-50718

CVE.ORG link : CVE-2023-50718


JSON object : View

Products Affected

nocodb

  • nocodb
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')