Mongoose - NoSQL Injection
Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2024-53900.
MongoosePoC 已收录
CVSS9.0
共找到 2 条公开漏洞记录
Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2024-53900.
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.