CVE-2020-35666

Steedos Platform through 1.21.24 allows NoSQL injection because the /api/collection/findone implementation in server/packages/steedos_base.js mishandles req.body validation, as demonstrated by MongoDB operator attacks such as an X-User-Id[$ne]=1 value.
References
Link Resource
https://github.com/steedos/steedos-platform/issues/1245 Exploit Vendor Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:steedos:steedos:*:*:*:*:*:*:*:*

Information

Published : 2020-12-23 12:15

Updated : 2020-12-23 12:29


NVD link : CVE-2020-35666

Mitre link : CVE-2020-35666


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advertisement

dedicated server usa

Products Affected

steedos

  • steedos