VDB
Sign up
MEDIUM6.1

GHSA-fffg-cwc9-xvj7

mongo-express Cross-site Request Forgery vulnerability

Details

In mongo-express 1.0.2, /admin allows CSRF, as demonstrated by deletion of a Collection.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mongo-express
Introduced in: 0

No fixed version published yet for mongo-express (npm). Pin to a known-safe version or switch to an alternative.

References