Impact
Budibase before version 3.40.0 is vulnerable to a cross‑site request forgery attack against its chat‑link handoff endpoint. An attacker who obtains a valid confirmation token can submit a POST request from a crafted phishing page, causing the server to bind the attacker’s external chat identity to the victim’s account. This allows the attacker to impersonate the victim in agent operations and inherit the victim’s permissions, effectively gaining unauthorized access to privileged actions.
Affected Systems
The vulnerability affects Budibase server. All deployments using Budibase versions prior to 3.40.0 are impacted.
Risk and Exploitability
The CVSS score of 8.7 categorizes this flaw as high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw by hosting a malicious page that automatically submits a POST request with a leaked confirmation token, triggering the server to bind the attacker’s chat identity. If the attacker succeeds, they will be able to act as the victim with the victim’s permissions. Due to the ease of exploitation through phishing and the severe impact, the risk is significant.
OpenCVE Enrichment