Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q7pj-xc3r-rm4w

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Steedos Platform through 1.21.24 allows NoSQL injection because the /api/collection/findone implementation in server/packages/steedos_base.js mishandles req.body validation, as demonstrated by MongoDB operator attacks such as an X-User-Id[$ne]=1 value.

Steedos Platform through 1.21.24 allows NoSQL injection because the /api/collection/findone implementation in server/packages/steedos_base.js mishandles req.body validation, as demonstrated by MongoDB operator attacks such as an X-User-Id[$ne]=1 value.

EPSS

Процентиль: 61%
0.00421
Низкий

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.8
nvd
около 5 лет назад

Steedos Platform through 1.21.24 allows NoSQL injection because the /api/collection/findone implementation in server/packages/steedos_base.js mishandles req.body validation, as demonstrated by MongoDB operator attacks such as an X-User-Id[$ne]=1 value.

EPSS

Процентиль: 61%
0.00421
Низкий

Дефекты

CWE-89