logo

Appsmith Vulnerabilities Can be Chained to Achieve 1-Click Admin Account Takeover

ID: 0e7ac5ca-1499-5124-a2e8-a70f242531b6

STIX ID: report--0e7ac5ca-1499-5124-a2e8-a70f242531b6

Feed Name: CloudSEK Blog

Threat Score
75/100

Date Published: 2023-01-09

Date Updated: 2026-04-27

...
...

CloudSEK researchers disclose a chained Appsmith vulnerability: an iframe srcDoc XSS allows an attacker to exfiltrate admin-only environment variables (including internal MongoDB credentials), which can then be used via the platform's MongoDB data-source functionality to connect to the internal database and modify user policies to escalate privileges to administrator. The report includes proof-of-concept code, screenshots of successful exfiltration and DB access, impact analysis noting >1000 internet-exposed Appsmith instances, and remediation advice (Appsmith patched the issues in versions 1.7.12+ and recommends domain whitelisting).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.