logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2023-35843

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2023-35843

Description:
NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access arbitrary files on the server by manipulating the path parameter of the /download route. This vulnerability could allow an attacker to access sensitive files and data on the server, including configuration files, source code, and other sensitive information.
Last updated date:
12/12/2024

Reports

alt

ACTIVELY EXPLOITED

Type:
exploitation
Confidence:
HIGH
Date of publishing:
09/18/2024
Reference url to background

https://media.defense.gov/2024/Sep/18/2003547016/-1/-1/1/CSA-PRC-LINKED-ACTORS-BOTNET.PDF

Type:
exploit
Confidence:
HIGH
Date of publishing:
06/29/2023
Reference url to background

https://advisory.dw1.io/60

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy