CyberRota Analysis
AI-GeneratedDatabasement versions prior to 1.7.14 are vulnerable due to improper validation of invitation tokens, allowing attackers to exploit cached authorization decisions. This flaw enables unauthorized users to overwrite account passwords and gain access to sensitive database credentials if they obtain a leaked or forwarded invitation link. Organizations using affected versions should prioritize patching this vulnerability to mitigate the risk of unauthorized access to critical data.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching the authorization decision without re-checking token validity during acceptance. Attackers with a leaked or forwarded invitation link can load the page while pending, then accept the invitation after the legitimate user has already accepted it to overwrite the account password and gain authenticated access to managed database credentials and secrets.