GHSA-jw66-5j32-j2m2HighCVSS 8.8

DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users...

Published
September 3, 2026
Last Modified
September 3, 2026

🔗 CVE IDs covered (1)

📋 Description

DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and write arbitrary files via file:// scheme resolution. Attackers can exploit getJslFileName() to bypass directory containment and access sensitive files including encrypted database credentials stored in connections configuration.

🔗 References (7)