Vulnerabilities/

Privilege Escalation due to Blind NoSQL Injection in flintcms

Severity:
High

Description

Versions of flintcms before version 1.1.10 are vulnerable to account takeover due to blind MongoDB injection in the password reset.

Recommendation

Update the flintcms package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
flintcms
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing