Cross-site scripting
High severity
GitHub Reviewed
Published
Jun 19, 2021
in
mongo-express/mongo-express
•
Updated Feb 1, 2023
Description
Reviewed
Jun 21, 2021
Published by the National Vulnerability Database
Jun 21, 2021
Published to the GitHub Advisory Database
Jun 28, 2021
Last updated
Feb 1, 2023
Two kinds of XSS were found:
Impact
As an example of type 1 attack, an unauthorized user who only can send a large amount of data in a field of a document may use this payload:
This will send an export of a collection to the attacker without even admin knowing. Other types of attacks such as dropping a database\collection are also possible.
Patches
Upgrade to
v1.0.0-alpha.4
For more information
If you have any questions or comments about this advisory:
References