CVE-2020-35666

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
23/12/2020
Last modified:
23/12/2020

Description

Steedos Platform through 1.21.24 allows NoSQL injection because the /api/collection/findone implementation in server/packages/steedos_base.js mishandles req.body validation, as demonstrated by MongoDB operator attacks such as an X-User-Id[$ne]=1 value.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:steedos:steedos:*:*:*:*:*:*:*:* 1.21.24 (including)


References to Advisories, Solutions, and Tools