In NocoDB prior to 0.91.7, the SMTP plugin doesn't have verification or validation. This allows attackers to make requests to internal servers and read the contents.
{ "github_reviewed_at": "2023-06-30T20:40:22Z", "cwe_ids": [ "CWE-200", "CWE-209", "CWE-918" ], "nvd_published_at": "2022-06-13T12:15:00Z", "severity": "HIGH", "github_reviewed": true }