NocoDB information disclosure vulnerability
High severity
GitHub Reviewed
Published
Jun 14, 2022
to the GitHub Advisory Database
•
Updated Jun 30, 2023
Description
Published by the National Vulnerability Database
Jun 13, 2022
Published to the GitHub Advisory Database
Jun 14, 2022
Reviewed
Jun 30, 2023
Last updated
Jun 30, 2023
In NocoDB prior to 0.91.7, the SMTP plugin doesn't have verification or validation. This allows attackers to make requests to internal servers and read the contents.
References