🛡️ CVE Monitor
Dịch vụ / phần mềm liên quan: MySQL / MariaDB

Mô tả

Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backend-core/src/sql/sqlTable.ts by interpolating identifiers directly into a raw query string (backtick-quoted for MySQL, a single-quoted sp_rename literal for MSSQL) without applying the project's quoteMySqlIdentifier / quoteSqlServerIdentifier helpers. An attacker with DDL rights on a connected MySQL/MSSQL datasource can create a column whose name contains a backtick (MySQL) or single quote (MSSQL) plus additional SQL; Budibase's schema introspection stores the name verbatim, and when a Budibase builder later renames that column through the UI (POST /api/tables with _rename.old), the embedded quote character terminates the identifier and the injected SQL is executed. Because the MySQL connection is opened with multipleStatements: true, stacked statements run as Budibase's datasource user, allowing arbitrary reads, writes, or destructive operations on the connected database outside Budibase's row/table permission model. Fixed in 3.45.0.

Chi tiết

Trạng tháiDeferred
Điểm CVSS8.0 (v3.1)
Vector CVSSCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Ngày công bố21:16 26/09/2026
Ngày cập nhật01:17 29/09/2026
Nguồn dữ liệunvd

CWE

  • CWE-89

Sản phẩm bị ảnh hưởng

Nguồn dữ liệu chưa cung cấp thông tin sản phẩm chi tiết.

Tài liệu tham khảo

Lịch sử thay đổi

Thời gianLoạiTrườngGiá trị cũGiá trị mới
01:17 29/09/2026 MODIFIED modified_at 2026-09-28T16:36:05Z 2026-09-28T18:17:15Z
23:37 28/09/2026 CREATED cve HIGH

Tất cả thời gian trên trang này hiển thị theo giờ Việt Nam (GMT+7).