MEDIUM6.1
GHSA-fffg-cwc9-xvj7
mongo-express Cross-site Request Forgery vulnerability
Details
In mongo-express 1.0.2, /admin allows CSRF, as demonstrated by deletion of a Collection.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/mongo-express
Introduced in:
0No fixed version published yet for mongo-express (npm). Pin to a known-safe version or switch to an alternative.