NocoDB is software for building databases as spreadsheets. Prior to version 0.202.10, an authenticated attacker with create access could conduct a SQL Injection attack on MySQL DB using unescaped `table_name`. This vulnerability may result in leakage of sensitive data in the database. Version 0.202.10 contains a patch for the issue.
Metrics
Affected Vendors & Products
References
History
Thu, 21 Aug 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Xgenecloud
Xgenecloud nocodb |
|
CPEs | cpe:2.3:a:xgenecloud:nocodb:*:*:*:*:*:*:*:* | |
Vendors & Products |
Xgenecloud
Xgenecloud nocodb |

Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-05-13T16:08:09.198Z
Updated: 2024-08-21T20:46:16.025Z
Reserved: 2023-12-11T17:53:36.030Z
Link: CVE-2023-50718

Updated: 2024-08-02T22:16:47.369Z

Status : Analyzed
Published: 2024-05-14T14:17:02.857
Modified: 2025-08-21T17:02:08.693
Link: CVE-2023-50718

No data.