216.73.216.226

CVE-2023-35843

· Published 19/06/2023 20:15 · Modified 21/12/2025 07:34 · Author: The MITRE Corporation

Labels: CVE-2023-35843

Essential information

Published
19/06/2023 20:15
Modified
21/12/2025 07:34
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/C:H/I:N/A:N

CVSS metrics

Description

NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access arbitrary files on the server by manipulating the path parameter of the /download route. This vulnerability could allow an attacker to access sensitive files and data on the server, including configuration files, source code, and other sensitive information.

NVD status

NVD
View on NVD