Impact
Starlette-admin versions 0.16.1 through 0.17.1 do not honor the searchable_fields allowlist when it is configured as an empty list. This flaw lets authenticated users construct structured filter queries via the list API’s where parameter, enabling equality and comparison operations on columns that are intended to be non-searchable. The weakness is identified as CWE-863, allowing attackers to retrieve or manipulate data in fields that should be hidden, exposing sensitive information and potentially affecting data integrity.
Affected Systems
The vulnerable product is jowilf’s Starlette-admin. Affected releases are 0.16.1 through 0.17.1, covering all intermediate versions. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of < 1% suggests a very low probability of exploitation, and it is not listed in CISA’s KEV catalog. The likely attack vector is an authenticated API request to the list endpoint, where an attacker uses the where parameter to craft structured filter queries. Based on the description, it is inferred that only valid authenticated user credentials are required to send such stated. The attacker can perform equality and comparison operations on columns that are intended to be non‑searchable, enabling unauthorized data exposure.
OpenCVE Enrichment