Description
mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.
Published: 2026-09-08
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Potential Data Theft via Unchecked SQL Parameter
Action: Apply Fix
AI Analysis

Impact

The vulnerability stems from a lack of input validation on the tableName parameter sent to the /sys/dbConnect/data endpoint of mfish‑nocode‑pro. By injecting malicious SQL code, an attacker can manipulate the query constructed by the application, leading to unauthorized retrieval of database contents. This flaw aligns with the classic SQL injection weakness and can compromise the confidentiality of sensitive data.

Affected Systems

The affected product is mfish‑nocode‑pro, version 1.0.0. No other vendors or versions are listed as impacted.

Risk and Exploitability

The vulnerability is a SQL injection (CWE‑89) with a CVSS score of 9.8, indicating a critical severity. The EPSS score, which estimates how likely the flaw is to be exploited, is < 1%, suggesting very low current exploitation probability, and the flaw is not listed in CISA's KEV catalog. The attack vector is likely network-based, with an attacker sending a crafted request to the /sys/dbConnect/data endpoint containing a malicious tableName value. Successful exploitation would allow the attacker to read sensitive database contents and potentially modify data, depending on database user privileges.

Generated by OpenCVE AI on September 10, 2026 at 04:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a patched version of mfish‑nocode‑pro once an official fix is released.
  • Validate and sanitize the tableName parameter to allow only expected table identifiers before using it in a query.
  • Configure the database user that the application uses with the least privileges necessary, preventing full data disclosure if the injection is exploited.

Generated by OpenCVE AI on September 10, 2026 at 04:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Title SQL Injection via Unvalidated Table Name in mfish‑nocode‑pro

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Title SQL Injection via Unvalidated Table Name in mfish‑nocode‑pro
Weaknesses CWE-89

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-09T15:14:09.566Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79570

cve-icon Vulnrichment

Updated: 2026-09-09T15:14:03.858Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T17:18:31.253

Modified: 2026-09-09T16:17:07.000

Link: CVE-2026-79570

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T04:15:14Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')