PT-2026-69942 · Dataease+1 · Sqlbot
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SQLBot versions prior to 1.10.0 commit c3f40a5
Description
The SQText dashboard component renders TinyMCE output using
v-html without proper sanitization. This allows attackers with permissions to modify dashboard text widget content to inject arbitrary HTML and JavaScript, which then executes in the browser of any user viewing the dashboard.Recommendations
Update SQLBot to the version containing commit c3f40a5.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sqlbot