Vulnerabilities > CVE-2019-10758 - Unspecified vulnerability in Mongo-Express Project Mongo-Express

047910
CVSS 9.9 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
mongo-express-project
critical

Summary

mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.

Vulnerable Configurations

Part Description Count
Application
Mongo-Express_Project
72