Vulnerabilities (CVE)

Filtered by vendor Flask-appbuilder Project Subscribe
Filtered by product Flask-appbuilder
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-34110 1 Flask-appbuilder Project 1 Flask-appbuilder 2024-11-21 N/A 2.7 LOW
Flask-AppBuilder is an application development framework, built on top of Flask. Prior to version 4.3.2, an authenticated malicious actor with Admin privileges, could by adding a special character on the add, edit User forms trigger a database error, this error is surfaced back to this actor on the UI. On certain database engines this error can include the entire user row including the pbkdf2:sha256 hashed password. This vulnerability has been fixed in version 4.3.2.