Lucene search

K
osvGoogleOSV:GHSA-JHQ3-57XH-6643
HistoryAug 21, 2018 - 5:03 p.m.

Privilege Escalation due to Blind NoSQL Injection in flintcms

2018-08-2117:03:59
Google
osv.dev
8

EPSS

0.004

Percentile

73.9%

Versions of flintcms before version 1.1.10 are vulnerable to account takeover due to blind MongoDB injection in the password reset.

Recommendation

Update to version 1.1.10 or later.

EPSS

0.004

Percentile

73.9%