NocoDB is software for building databases as spreadsheets. Starting in verson 0.202.6 and prior to version 0.202.10, an attacker can upload a html file with malicious content. If user tries to open that file in browser malicious scripts can be executed leading stored cross-site scripting attack. This allows remote attacker to execute JavaScript code in the context of the user accessing the vector. An attacker could have used this vulnerability to execute requests in the name of a logged-in user or potentially collect information about the attacked user by displaying a malicious form. Version 0.202.10 contains a patch for the issue.
Metrics
Affected Vendors & Products
References
History
Thu, 21 Aug 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Xgenecloud
Xgenecloud nocodb |
|
CPEs | cpe:2.3:a:xgenecloud:nocodb:*:*:*:*:*:*:*:* | |
Vendors & Products |
Xgenecloud
Xgenecloud nocodb |

Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-05-13T16:05:48.148Z
Updated: 2024-08-02T22:16:47.335Z
Reserved: 2023-12-11T17:53:36.030Z
Link: CVE-2023-50717

Updated: 2024-08-02T22:16:47.335Z

Status : Analyzed
Published: 2024-05-14T14:17:01.190
Modified: 2025-08-21T16:58:23.877
Link: CVE-2023-50717

No data.