CVE-2020-35666: SQL Injection
Published Dec 23, 2020
·Updated
Steedos Platform through 1.21.24 allows NoSQL injection because the /api/collection/findone implementation in server/packages/steedosbase.js mishandles req.body validation, as demonstrated by MongoDB operator attacks such as an X-User-Id[$ne]=1 value.
Affected Software
1 affected component
Steedos Steedos<=1.21.24
Event History
Dec 23, 2020
CVE Published
via MITRE·07:49 PM
Data Sourced
via MITRE·07:49 PM
Description