Tag
critical
advisory
SQL Injection Vulnerability in Budibase MySQL Integration
1 rule 7 TTPsA critical SQL injection vulnerability was discovered in Budibase's MySQL integration (versions <= 3.38.1) that allows remote attackers to execute arbitrary SQL commands through user input fields due to the `multipleStatements: true` configuration, leading to complete database compromise.
Budibase Server +1
sql-injection
web-application
vulnerability
nosql-injection
data-exfiltration
data-destruction
application-vulnerability
csrft
+4
1r
7t
high
advisory
Real-World SIM Swap and Near Account Takeover Exploits Identity Verification Failures
5 TTPsAn unspecified attacker conducted a sophisticated SIM swap and identity attack against a personal wireless account by employing social engineering (vishing) to steal an SMS-based One-Time Passcode and account PIN, facilitating session hijacking and unauthorized account modifications like mobile number cancellation, demonstrating critical weaknesses in point-in-time identity verification and the need for continuous risk assessment.
sim-swap
social-engineering
account-takeover
identity-theft
mfa-bypass
telecommunications
5t