9.9

CVE-2026-41478

Saltcorn: SQL Injection via Unparameterized Sync Endpoints (maxLoadedId)

Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.6, 1.5.6, and 1.6.0-beta.5, a SQL injection vulnerability in Saltcorn’s mobile-sync routes allows any authenticated low-privilege user with read access to at least one table to inject arbitrary SQL through sync parameters. This can lead to full database exfiltration, including admin password hashes and configuration secrets, and may also enable database modification or destruction depending on the backend. This vulnerability is fixed in 1.4.6, 1.5.6, and 1.6.0-beta.5.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Saltcorn ≫ Saltcorn Version < 1.4.6
Saltcorn ≫ Saltcorn Version >= 1.5.0 < 1.5.6
Saltcorn ≫ Saltcorn Version 1.6.0 Update alpha0
Saltcorn ≫ Saltcorn Version 1.6.0 Update alpha1
Saltcorn ≫ Saltcorn Version 1.6.0 Update alpha10
Saltcorn ≫ Saltcorn Version 1.6.0 Update alpha11
Saltcorn ≫ Saltcorn Version 1.6.0 Update alpha12
Saltcorn ≫ Saltcorn Version 1.6.0 Update alpha13
Saltcorn ≫ Saltcorn Version 1.6.0 Update alpha14
Saltcorn ≫ Saltcorn Version 1.6.0 Update alpha15
Saltcorn ≫ Saltcorn Version 1.6.0 Update alpha16
Saltcorn ≫ Saltcorn Version 1.6.0 Update alpha17
Saltcorn ≫ Saltcorn Version 1.6.0 Update alpha2
Saltcorn ≫ Saltcorn Version 1.6.0 Update alpha3
Saltcorn ≫ Saltcorn Version 1.6.0 Update alpha4
Saltcorn ≫ Saltcorn Version 1.6.0 Update alpha5
Saltcorn ≫ Saltcorn Version 1.6.0 Update alpha6
Saltcorn ≫ Saltcorn Version 1.6.0 Update alpha7
Saltcorn ≫ Saltcorn Version 1.6.0 Update alpha8
Saltcorn ≫ Saltcorn Version 1.6.0 Update alpha9
Saltcorn ≫ Saltcorn Version 1.6.0 Update beta1
Saltcorn ≫ Saltcorn Version 1.6.0 Update beta2
Saltcorn ≫ Saltcorn Version 1.6.0 Update beta3
Saltcorn ≫ Saltcorn Version 1.6.0 Update beta4
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.26% 0.175
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 9.9 3.1 6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

https://github.com/saltcorn/saltcorn/security/advisories/GHSA-jp74-mfrx-3qvh
Vendor Advisory