Vendor
NocoBase Authenticated SQL Injection to RCE
1 rule 2 TTPs 1 CVEA critical SQL injection vulnerability in NocoBase allows authenticated attackers to achieve remote code execution on the underlying PostgreSQL container via stacked statements.
NocoBase 2.0.27 VM Sandbox Escape Vulnerability
2 rulesA local exploit has been published for NocoBase 2.0.27, detailing a VM Sandbox Escape vulnerability, increasing the risk to unpatched systems.
NocoBase SQL Injection via Missing Validation on Update Endpoint
2 rules 1 TTPA SQL injection vulnerability exists in nocobase plugin-collection-sql versions 2.0.32 and earlier due to missing validation on the sqlCollection:update endpoint, allowing attackers with collection management permissions to execute arbitrary SQL queries and exfiltrate data.
NocoBase SQL Injection via Recursive Eager Loading
2 rules 4 TTPsNocoBase versions 2.0.32 and earlier are vulnerable to SQL injection due to string concatenation in the `queryParentSQL()` function, allowing attackers with record creation permissions to inject arbitrary SQL and potentially extract sensitive information or execute commands.