SQL Injection Vulnerability in Saltcorn Database Application Builder
⚠️ CVE-Referenzen:
CVE-2026-41478
Saltcorn - Saltcorn - CRITICAL - CVE-2026-41478.
The Saltcorn database application builder is prone to a SQL injection vulnerability in its mobile-sync routes. This issue affects authenticated low-privilege users who have read access to at least one table, enabling them to inject arbitrary SQL through the sync parameters. The exploitation of this vulnerability can lead to the exfiltration of sensitive data, such as admin password hashes and configuration secrets stored in the database. Furthermore, it poses risks of potential modification or destruction of data based on the backend configuration. The issue has been addressed in Saltcorn versions 1.4.6, 1.5.6, and 1.6.0-beta.5.
Quelle: securityvulnerability.io