Lucene search

K
nodejsBenoit Cรดtรฉ-JodoinNODEJS:689
HistoryAug 16, 2018 - 7:44 p.m.

Privilege Escalation due to Blind NoSQL Injection

2018-08-1619:44:22
Benoit Cรดtรฉ-Jodoin
www.npmjs.com
13

EPSS

0.004

Percentile

73.9%

Overview

Versions of flintcms before version 1.1.10 are vulnerable to account takeover due to blind MongoDB injection in the password reset.

Recommendation

Update to version 1.1.10 or later.

References

EPSS

0.004

Percentile

73.9%