Improper Privilege Management in GitHub repository nocodb/nocodb prior to 0.91.7+.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://huntr.dev/bounties/156f405b-21d6-4384-9bff-17ebfe484e20 | patch third party advisory exploit |
https://github.com/nocodb/nocodb/commit/269a19c2ad89a0e8a7596498e3806ff2ec1040c2 | third party advisory patch |