GHSA-q6x4-v3qx-85qw
Budibase: SQL Injection via `multipleStatements: true`
Details
## Summary A critical SQL injection vulnerability was discovered in Budibase's MySQL integration that allows remote attackers to execute arbitrary SQL commands.
## Details ### Vulnerability Type SQL Injection
### Description The MySQL integration component in Budibase is configured with `multipleStatements: true`, enabling execution of multiple SQL statements in a single query. Attackers can inject malicious SQL commands through user input fields, leading to complete database compromise.
### Location ```typescript // File: packages/server/src/integrations/mysql.ts // Line: 173
this.config = { ...config, typeCast: defaultTypeCasting, multipleStatements: true, // VULNERABLE timezone: "Z", } ```
## Proof of Concept
### Exploit ```javascript const mysql = require('mysql2');
// Budibase vulnerable configuration const connection = mysql.createConnection({ host: 'localhost', user: 'root', password: 'password', multipleStatements: true, // Vulnerable setting timezone: "Z" });
// Attack: Data destruction connection.query( `SELECT * FROM users WHERE id = 1; DROP TABLE sensitive_data; --`, (err, results) => { if (!err) console.log("Table dropped successfully"); } ); ```
## Impact - **Data Destruction**: Execute DROP TABLE, DELETE commands - **Data Theft**: Exfiltrate data via SELECT INTO OUTFILE - **Privilege Escalation**: Grant database admin privileges - **Denial of Service**: Disrupt service operations - **Complete Database Compromise**: Full control over database
## Remediation ### Patch ```diff --- a/packages/server/src/integrations/mysql.ts +++ b/packages/server/src/integrations/mysql.ts @@ -170,7 +170,7 @@ class MySQLIntegration extends Sql implements DatasourcePlus { this.config = { ...config, typeCast: defaultTypeCasting, - multipleStatements: true, + multipleStatements: false, timezone: "Z", } } ```
### Workarounds 1. Temporarily disable MySQL integration 2. Implement web application firewall (WAF) 3. Restrict database user privileges
Are you affected?
Enter the version of the package you're using.
Affected packages
0 No fixed version published yet for @budibase/server (npm). Pin to a known-safe version or switch to an alternative.