CyberSec.Space Logo
Back to CVE Browser

CVE-2020-24391

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1610%
EPSS Percentile36.78th
PublishedMar 30, 2021
Last ModifiedNov 21, 2024

Vulnerability Description

mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this may overlap CVE-2019-10769.

Affected Platforms (CPE)

πŸ“¦
Mongo Express Project

Mongo Express

<= 0.54.0

References & Advisories

Related Vulnerabilities