Junglewise Threat Intelligence

CVE-2021-23404: PYSEC-2021-332 - This affects all versions of package sqlite-web. The SQL dashboard area allows sensitive actions to be performed without validating that the

CVE-2021-23404 · Severity: low · CVSS 3.1 · Published 2021-09-08

Vendors: PyPI.

Executive brief

sqlite-web is a Python web application that provides a SQL database browser interface for SQLite files. A CSRF vulnerability in the SQL dashboard allows unauthenticated attackers to trick a logged-in user into performing unauthorized database operations (such as modifications or queries) by visiting a malicious website. This could enable data manipulation, deletion, or exposure without the user's knowledge.

Technical details

The vulnerability is a Cross-Site Request Forgery (CWE-352) affecting the SQL dashboard in sqlite-web. The vulnerable component fails to validate that sensitive database operations originate from legitimate application requests, allowing attackers to forge requests via victim browsers. The attack requires user interaction (victim must be logged in and visit attacker-controlled page) but no authentication is needed on the attacker's side. An attacker can execute arbitrary SQL commands, modify database contents, or extract sensitive data through a victim's authenticated session. All versions up to and including 0.6.5 are affected.

Affected products

  • sqlite-web sqlite-web 0.1.1 through 0.6.5

Timeline

  • 2021-09-09: disclosed
  • 2021-09-08: advisory: NVD publication

References