Apache Superset through 1.3.2 contains a default login vulnerability via registered database connections for authenticated users. An attacker can obtain access to user accounts and thereby obtain sensitive information, modify data, and/or execute unauthorized operations.
View the template here CVE-2021-44451.yaml
References:
https://github.com/ARPSyndicate/cvemon