CVE-2023-52555 Information

Description

In mongo-express 1.0.2 /admin allows CSRF as demonstrated by deletion of a Collection.

Reference

https://github.com/mongo-express/mongo-express/issues/1338

Share on: