Junglewise Threat Intelligence

CVE-2023-49781: NocoDB stored cross-site scripting in Formula component

CVE-2023-49781 · Severity: low · CVSS 3.1 · Published 2024-05-13

Technologies: nocodb (npm). Vendors: NocoDB, npm.

Executive brief

NocoDB is a popular open-source database management platform that allows users to create and share databases through a web interface. A stored cross-site scripting vulnerability in the formula field component allows attackers to inject malicious code into shared tables; when victims open the attacker's shared link, the injected JavaScript executes and steals session credentials stored in the browser.

Technical details

The vulnerability exists in nc-gui/components/virtual-cell/Formula.vue, which renders user-controlled content via a v-html tag after processing through replaceUrlsWithLink(). This function only sanitizes a specific URI::(XXX) pattern and creates hyperlinks from it, but leaves all other HTML/JavaScript unchanged. An authenticated attacker can craft a formula field containing malicious JavaScript (e.g., <img src=1 onerror="malicious code"URI::(XXX)>) and share the table publicly; victims who view the shared link will have the payload executed in their browser context, allowing credential theft. The attack requires the victim to click the shared link (user interaction) and login status. The fix is available in version 0.202.9 and later.

Affected products

  • NocoDB NocoDB < 0.202.9

Timeline

  • 2024-05-13: disclosed
  • 2024-05-13: patched: Fixed in version 0.202.9

References

Related threats