PT-2026-71909 · Budibase+1 · Budibase+1
CVSS v4.0
8.8
High
| Vector | AV:N/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Budibase versions prior to 3.40.0
Description
A SQL injection issue exists in the Oracle datasource connector during the post-write row lookup process. The system fails to properly escape table names used in identifiers. An attacker with write permissions on a table containing a double-quote in its name can inject SQL commands. These commands execute with the privileges of the datasource database user, allowing the attacker to read or modify arbitrary data.
Recommendations
Update to version 3.40.0 or later.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Budibase
Oracle