CVE-2018-8097

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
14/03/2018
Last modified:
10/04/2018

Description

io/mongo/parser.py in Eve (aka pyeve) before 0.7.5 allows remote attackers to execute arbitrary code via Code Injection in the where parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:python-eve:eve:*:*:*:*:*:*:*:* 0.7.5 (excluding)