Impact
Adalo’s no‑code app builder (versions 1 and 2) allows an attacker to enumerate database identifiers (dbId) and retrieve full user records. The platform does not enforce data minimization or privacy‑by‑design safeguards, so personal identifiers and other sensitive data can be exposed to unauthorized actors.
Affected Systems
The vulnerability exists in Adalo No‑Code App Builder releases 1 and 2. Attackers can enumerate database identifiers to retrieve full user records.
Risk and Exploitability
The flaw carries a CVSS score of 7.5, indicating a medium‑to‑high severity data‑exposure risk. The EPSS score of less than 1 % confirms a low probability of exploitation in the wild. Based on the description, it is inferred that the dbId parameter can be queried without authentication, making the vulnerability potentially exploitable once an attacker discovers valid identifiers. The likely attack vector is through the public API where dbId is accepted.
OpenCVE Enrichment