Impact
A flaw in the update_resource and update_canvas endpoints of SQLBot up to version 1.10.1 allows an authenticated workspace member to supply any dashboard identifier and perform modifications on dashboards that the user does not own. The application fails to verify ownership before applying changes, permitting attackers to rename dashboards and overwrite component data, canvas styles, and view information that belong to other workspace members. This results in integrity violations and potential exposure of private configuration details, and could facilitate escalation within the workspace if sensitive metadata is altered.
Affected Systems
The vulnerability applies to DataEase’s SQLBot product, versions 1.10.1 and earlier. No additional vendor or product versions are listed in the advisory.
Risk and Exploitability
The CVSS score of 7.1 indicates a high level of severity. The EPSS score is less than 1%, indicating a low probability of exploitation, and the lack of a KEV listing suggests no known active attacks yet. Attackers must be authenticated members of a workspace to gain access to the endpoints, but because ownership checks are omitted, any legitimate session within that workspace can be abused to tamper with other users’ dashboards.
OpenCVE Enrichment