9.9

CVE-2026-41478

Saltcorn: SQL Injection via Unparameterized Sync Endpoints (maxLoadedId)

Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.6, 1.5.6, and 1.6.0-beta.5, a SQL injection vulnerability in Saltcorn’s mobile-sync routes allows any authenticated low-privilege user with read access to at least one table to inject arbitrary SQL through sync parameters. This can lead to full database exfiltration, including admin password hashes and configuration secrets, and may also enable database modification or destruction depending on the backend. This vulnerability is fixed in 1.4.6, 1.5.6, and 1.6.0-beta.5.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SaltcornSaltcorn Version < 1.4.6
SaltcornSaltcorn Version >= 1.5.0 < 1.5.6
SaltcornSaltcorn Version1.6.0 Updatealpha0
SaltcornSaltcorn Version1.6.0 Updatealpha1
SaltcornSaltcorn Version1.6.0 Updatealpha10
SaltcornSaltcorn Version1.6.0 Updatealpha11
SaltcornSaltcorn Version1.6.0 Updatealpha12
SaltcornSaltcorn Version1.6.0 Updatealpha13
SaltcornSaltcorn Version1.6.0 Updatealpha14
SaltcornSaltcorn Version1.6.0 Updatealpha15
SaltcornSaltcorn Version1.6.0 Updatealpha16
SaltcornSaltcorn Version1.6.0 Updatealpha17
SaltcornSaltcorn Version1.6.0 Updatealpha2
SaltcornSaltcorn Version1.6.0 Updatealpha3
SaltcornSaltcorn Version1.6.0 Updatealpha4
SaltcornSaltcorn Version1.6.0 Updatealpha5
SaltcornSaltcorn Version1.6.0 Updatealpha6
SaltcornSaltcorn Version1.6.0 Updatealpha7
SaltcornSaltcorn Version1.6.0 Updatealpha8
SaltcornSaltcorn Version1.6.0 Updatealpha9
SaltcornSaltcorn Version1.6.0 Updatebeta1
SaltcornSaltcorn Version1.6.0 Updatebeta2
SaltcornSaltcorn Version1.6.0 Updatebeta3
SaltcornSaltcorn Version1.6.0 Updatebeta4
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.26% 0.175
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 9.9 3.1 6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

https://github.com/saltcorn/saltcorn/security/advisories/GHSA-jp74-mfrx-3qvh
Vendor Advisory