NoSQL Injection Vulnerability in Steedos Platform by Steedos
CVE-2020-35666
8.8HIGH
What is CVE-2020-35666?
The Steedos Platform, up to version 1.21.24, is prone to NoSQL injection due to inadequate validation of the req.body in the /api/collection/findone endpoint. This vulnerability can be exploited using various MongoDB operators to manipulate queries, such as employing an X-User-Id[$ne]=1 parameter which can lead to unauthorized access or data compromise. Developers and administrators should apply necessary security patches and validations to mitigate potential exploitation.
