VDB
KO
CRITICAL 9.6

GHSA-q6x4-v3qx-85qw

Budibase: SQL Injection via `multipleStatements: true`

Details

## Summary A critical SQL injection vulnerability was discovered in Budibase's MySQL integration that allows remote attackers to execute arbitrary SQL commands.

## Details ### Vulnerability Type SQL Injection

### Description The MySQL integration component in Budibase is configured with `multipleStatements: true`, enabling execution of multiple SQL statements in a single query. Attackers can inject malicious SQL commands through user input fields, leading to complete database compromise.

### Location ```typescript // File: packages/server/src/integrations/mysql.ts // Line: 173

this.config = { ...config, typeCast: defaultTypeCasting, multipleStatements: true, // VULNERABLE timezone: "Z", } ```

## Proof of Concept

### Exploit ```javascript const mysql = require('mysql2');

// Budibase vulnerable configuration const connection = mysql.createConnection({ host: 'localhost', user: 'root', password: 'password', multipleStatements: true, // Vulnerable setting timezone: "Z" });

// Attack: Data destruction connection.query( `SELECT * FROM users WHERE id = 1; DROP TABLE sensitive_data; --`, (err, results) => { if (!err) console.log("Table dropped successfully"); } ); ```

## Impact - **Data Destruction**: Execute DROP TABLE, DELETE commands - **Data Theft**: Exfiltrate data via SELECT INTO OUTFILE - **Privilege Escalation**: Grant database admin privileges - **Denial of Service**: Disrupt service operations - **Complete Database Compromise**: Full control over database

## Remediation ### Patch ```diff --- a/packages/server/src/integrations/mysql.ts +++ b/packages/server/src/integrations/mysql.ts @@ -170,7 +170,7 @@ class MySQLIntegration extends Sql implements DatasourcePlus { this.config = { ...config, typeCast: defaultTypeCasting, - multipleStatements: true, + multipleStatements: false, timezone: "Z", } } ```

### Workarounds 1. Temporarily disable MySQL integration 2. Implement web application firewall (WAF) 3. Restrict database user privileges

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / @budibase/server
Introduced in: 0

No fixed version published yet for @budibase/server (npm). Pin to a known-safe version or switch to an alternative.

References