Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-5251

In parser-server before version 4.1.0, you can fetch all the users objects, by using regex in the NoSQL query. Using the NoSQL, you can use a regex on sessionToken and find valid accounts this way.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 48.5%
CVSS Severity
CVSS v3 Score 7.7
CVSS v2 Score 5.0
Products affected by CVE-2020-5251


Contact Us

Shodan ® - All rights reserved