Vulnerability Details CVE-2023-52555
In mongo-express 1.0.2, /admin allows CSRF, as demonstrated by deletion of a Collection.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 63.7%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2023-52555
-
cpe:2.3:a:mongo-express_project:mongo-express:1.0.2