Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 npm

NocoDB information disclosure vulnerability

GHSA-mx8q-jqwm-85mv · CVE-2022-2062

Published · Modified

Description

In NocoDB prior to 0.91.7, the SMTP plugin doesn't have verification or validation. This allows attackers to make requests to internal servers and read the contents.

Ready to move

Start Securing

Free, no credit card | First findings in minutes