Vulnerabilities > CVE-2019-10758 - Unspecified vulnerability in Mongo-Express Project Mongo-Express

047910
CVSS 9.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
mongo-express-project
critical

Summary

mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.

Vulnerable Configurations

Part Description Count
Application
Mongo-Express_Project
71