Baserow

Baserow

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 02.09.2026 03:29:38
  • Zuletzt bearbeitet 02.09.2026 19:23:13

Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula function. A low-privileged authenticated user who can create or modify formula fields can provide an undocumented fourth argument that is treated as a SQL template and interp...

  • EPSS 0.42%
  • Veröffentlicht 27.08.2026 14:50:42
  • Zuletzt bearbeitet 23.09.2026 17:17:43

Baserow dispatches an Application Builder data source without acting on the result of its permission check. The dispatch and record-name views in backend/src/baserow/contrib/builder/api/data_sources/views.py are declared with a permission class that ...

  • EPSS 0.2%
  • Veröffentlicht 24.08.2026 17:36:02
  • Zuletzt bearbeitet 23.09.2026 17:17:45

Baserow interpolates a user's display name into the rich-text mention markup without HTML encoding. PATCH /api/user/account/ stores the first_name value verbatim, and the mention renderer in web-frontend/modules/core/editor/mention.js builds its elem...

  • EPSS 0.2%
  • Veröffentlicht 04.08.2026 22:00:12
  • Zuletzt bearbeitet 12.08.2026 20:59:00

A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAuthTokenSerializer of the file backend/src/baserow/api/admin/users/serializers.py of the component Inactive Non-Staff User Handler. ...

  • EPSS 0.34%
  • Veröffentlicht 04.08.2026 21:45:08
  • Zuletzt bearbeitet 12.08.2026 20:59:00

A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_factor_auth/views.py of the component 2FA Verify Endpoint. Such manipulation leads to improper authen...

  • EPSS 1.29%
  • Veröffentlicht 20.08.2021 18:15:07
  • Zuletzt bearbeitet 21.11.2024 05:49:48

SSRF in URL file upload in Baserow <1.1.0 allows remote authenticated users to retrieve files from the internal server network exposed over HTTP by inserting an internal address.