NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query parameter is not properly sanitized, allowing unauthenticated, remote attackers to inject boolean-based blind and PostgreSQL error-based payloads.
Metrics
Affected Vendors & Products
References
History
Thu, 28 Aug 2025 07:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Nodebb
Nodebb nodebb |
|
Vendors & Products |
Nodebb
Nodebb nodebb |
Wed, 27 Aug 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-89 | |
Metrics |
cvssV3_1
|
Wed, 27 Aug 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query parameter is not properly sanitized, allowing unauthenticated, remote attackers to inject boolean-based blind and PostgreSQL error-based payloads. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-08-27T00:00:00.000Z
Updated: 2025-08-27T18:24:03.996Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-50979

Updated: 2025-08-27T18:22:22.520Z

Status : Awaiting Analysis
Published: 2025-08-27T18:15:45.820
Modified: 2025-08-29T16:24:09.860
Link: CVE-2025-50979

No data.