PT-2026-99354 · Budibase · Budibase
CVSS v4.0
8.9
High
| Vector | AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Budibase (@budibase/server) versions prior to 3.45.0
Description
An issue exists in the way MySQL and MSSQL column-rename DDL is constructed in
packages/backend-core/src/sql/sqlTable.ts. The software interpolates identifiers directly into a raw query string without using the quoteMySqlIdentifier or quoteSqlServerIdentifier helpers. An attacker with DDL rights on a connected datasource can create a column name containing a backtick for MySQL or a single quote for MSSQL, followed by malicious SQL. When a user renames this column via the UI using the 'POST /api/tables' endpoint with the rename.old parameter, the injected SQL is executed. In MySQL environments, the use of multipleStatements: true allows the execution of stacked statements, enabling arbitrary reads, writes, or destructive operations on the connected database, bypassing the row and table permission model.Recommendations
Update Budibase (@budibase/server) to version 3.45.0.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Budibase