Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A CVSS 9.8 authentication bypass in Budibase 3.31.4 and earlier allows unauthenticated access to every API endpoint via a regex injection in the webhook middleware. CISA has confirmed active exploitation, a public reverse shell exploit is available on GitHub, and no authentication or special privilege is required to trigger the flaw.

Author

Tech Jacks Solutions