Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-10758

mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.944
EPSS Ranking 100.0%
CVSS Severity
CVSS v3 Score 9.9
CVSS v2 Score 9.0
Proposed Action
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method.
Ransomware Campaign
Unknown
Products affected by CVE-2019-10758


Contact Us

Shodan ® - All rights reserved