PT-2026-95429 · Sqlbot · Sqlbot
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SQLBot versions prior to 1.10.2
Description
Authenticated workspace members can modify private dashboards belonging to other users because the system fails to verify dashboard ownership. By supplying arbitrary dashboard IDs to the 'update resource' and 'update canvas' endpoints, an attacker can rename dashboards and overwrite component data, canvas styles, and view information.
Recommendations
Update SQLBot to version 1.10.2 or later.
Restrict access to the 'update resource' and 'update canvas' endpoints to minimize the risk of unauthorized modifications.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sqlbot