Impact
Adalo No‑Code App Builder exposes data through a minimal leaderboard component that returns email addresses, UUIDs, and custom fields without requiring any application‑specific secrets. The weakness involves improper access control, insufficient authorization, and inadequate protection of credentials (CWE-284, CWE-285, CWE-613). A single HTTP request to this endpoint can harvest large amounts of personal information from any application.
Affected Systems
The vulnerability affects all installations of Adalo No‑Code App Builder (App Builder), regardless of version, as the issue is present in the default leaderboard component configuration. Specific version information is not supplied, therefore all current and legacy deployments are potentially impacted.
Risk and Exploitability
The CVSS score is 7.5, indicating a high severity vulnerability. The EPSS score is less than 1%, suggesting low probability of exploitation in the near term, and it is not listed in the CISA KEV catalog. The exploitability is remote; attackers can obtain user records over the two‑week lifetime of the JWT. Since the JWTs are not revocable, the attack window extends across the entire validity period, enabling repeated harvesting of sensitive personal information.
OpenCVE Enrichment