CVE-2026-89267 | CVSS: 4.3 | 严重级别: MEDIUM
starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to perform equality and comparison operations on excluded columns.
参考链接:
• https://github.com/jowilf/starlette-admin
• https://github.com/jowilf/starlette-admin/blob/0.17.1/starlette_admin/views.py#L
• https://www.vulncheck.com/advisories/starlette-admin-0.16.1-through-0.17.1-searc
📌 数据来源: NVD 官方
⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。