Executive brief
Databasement is a self-hosted database backup manager that allows teams to manage database credentials and backups through a web interface. An attacker who obtains a pending invitation link can load the acceptance page while the invitation is valid, then later submit a password change to hijack the account even after the legitimate user has already accepted the invitation. This allows unauthorized access to the managed database credentials and backup data.
Technical details
The vulnerability stems from the mount() method in AcceptInvitation.php validating the invitation token only once when the page loads, but the accept() method does not re-validate the token before updating the user's password. An attacker can load the page with a valid pending token, then submit the form after the token has been invalidated (e.g., when the legitimate user accepts the invitation), successfully overwriting the password and gaining authenticated access. The fix in version 1.7.14 re-validates token validity during the accept action.
Affected products
- David-Crty Databasement before 1.7.14
Timeline
- 2026-09-22: disclosed