Budibase - Admin Installer
Detected Budibase admin setup checklist endpoint was publicly accessible with no admin user created, allowing unauthenticated users to complete setup and gain full platform control.
BudibasePoC 已收录
CVSS—
一个开源的低代码平台,用于构建内部工具、应用程序等。
共找到 2 条公开漏洞记录
Detected Budibase admin setup checklist endpoint was publicly accessible with no admin user created, allowing unauthenticated users to complete setup and gain full platform control.
Budibase <= 3.31.4 contains an authentication bypass caused by unanchored regex in authorized() middleware matching webhook path patterns in query strings, letting unauthenticated remote attackers access any server-side API endpoint, exploit requires crafted request with webhook pattern in URL.