Privilege Escalation due to Blind NoSQL Injection in flintcms
Critical severity
GitHub Reviewed
Published
Aug 21, 2018
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Published to the GitHub Advisory Database
Aug 21, 2018
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
Versions of
flintcms
before version 1.1.10 are vulnerable to account takeover due to blind MongoDB injection in the password reset.Recommendation
Update to version 1.1.10 or later.
References