CVE-2023-52555: CSRF
Published Mar 1, 2024
·Updated
In mongo-express 1.0.2, /admin allows CSRF, as demonstrated by deletion of a Collection.
Affected Software
2 affected components
npm/mongo-express<=1.0.2
Mongo-express Project Mongo-express=1.0.2
Event History
Mar 1, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Advisory Published
via GitHub·09:31 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-52555?
CVE-2023-52555 is categorized as a high-severity vulnerability due to its potential for CSRF attacks.
2
How do I fix CVE-2023-52555?
To mitigate CVE-2023-52555, upgrade mongo-express to version 1.0.3 or later.
3
What type of vulnerability is CVE-2023-52555?
CVE-2023-52555 is a Cross-Site Request Forgery (CSRF) vulnerability.
4
What impact does CVE-2023-52555 have on my application?
CVE-2023-52555 could allow an attacker to delete collections in the mongo-express application without authorization.
5
Is CVE-2023-52555 present in earlier versions of mongo-express?
Yes, CVE-2023-52555 affects mongo-express versions up to and including 1.0.2.