Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-53900 PoC — Automattic Mongoose 安全漏洞

Source
Associated Vulnerability
Title:Automattic Mongoose 安全漏洞 (CVE-2024-53900)
Description:Automattic Mongoose是一款用于异步环境的MongoDB对象建模工具。 Automattic Mongoose 8.8.3之前版本存在安全漏洞,该漏洞源于查询操作符使用不当。
Description
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
File Snapshot

id: CVE-2024-53900 info: name: Mongoose < 8.8.3 - Remote Code Execution author: h4mg severity ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.