In NocoDB prior to 0.91.7, the SMTP plugin doesn't have verification or validation. This allows attackers to make requests to internal servers and read the contents.
{
"cwe_ids": [
"CWE-200",
"CWE-209",
"CWE-918"
],
"github_reviewed": true,
"github_reviewed_at": "2023-06-30T20:40:22Z",
"nvd_published_at": "2022-06-13T12:15:00Z",
"severity": "HIGH"
}