Description
When a tenant admin is logged out of the root domain (e.g., saltcorn.com) but logged in to their own tenant space as admin, they can simply append /tenant/create to their tenant URL.
Recommendation
Update the @saltcorn/data package to the latest compatible version. Followings are version details:
Affected version(s): **>= 1.6.0-alpha.0, < 1.6.0-beta.2 >= 1.5.0-beta.0, < 1.5.2 < 1.4.4** Patched version(s): **1.6.0-beta.2 1.5.2 1.4.4**
References
Could your website be exposed too?
SmartScanner can check your website for @saltcorn/data: Tenant user role is used for tenant creation role check and gives you actionable findings to investigate.
Start a free scanRelated Issues
- @saltcorn/data vulnerable to SQL Injection via jsexprToSQL Literal Handler - Vulnerability
- Vercel Workflow Allows Webhook Creation with Predictable User-Specified Tokens - Vulnerability
- Vercel Workflow Allows Webhook Creation with Predictable User-Specified Tokens - workflow - Vulnerability
- Incorrect Account Used for Signing - eth-ledger-bridge-keyring - Vulnerability


