Executive brief
sqlite-web is a Python web application that provides a SQL database browser interface for SQLite files. A CSRF vulnerability in the SQL dashboard allows unauthenticated attackers to trick a logged-in user into performing unauthorized database operations (such as modifications or queries) by visiting a malicious website. This could enable data manipulation, deletion, or exposure without the user's knowledge.
Technical details
The vulnerability is a Cross-Site Request Forgery (CWE-352) affecting the SQL dashboard in sqlite-web. The vulnerable component fails to validate that sensitive database operations originate from legitimate application requests, allowing attackers to forge requests via victim browsers. The attack requires user interaction (victim must be logged in and visit attacker-controlled page) but no authentication is needed on the attacker's side. An attacker can execute arbitrary SQL commands, modify database contents, or extract sensitive data through a victim's authenticated session. All versions up to and including 0.6.5 are affected.
Affected products
- sqlite-web sqlite-web 0.1.1 through 0.6.5
Timeline
- 2021-09-09: disclosed
- 2021-09-08: advisory: NVD publication