CVE - Secure /Entities/<Entity Name>

Right now if you have an entity under Data and you’ll access

https://base44.app/api/apps/<App Name>/entities/<Entity Name> (which is very easy info to get from looking at the packets) - You can see the entire DB. This can expose passwords/Data from any website built on top of base44.

Please authenticate to join the conversation.

Upvoters
Status

In Review

Board
💡

Feature Request

Date

About 1 year ago

Author

orel damari

Subscribe to post

Get notified by email when there are changes.