mongo-express@1.0.1 vulnerabilities

Web-based admin interface for MongoDB

  • latest version

    1.1.0-rc-3

  • latest non vulnerable version

  • first published

    13 years ago

  • latest version published

    6 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the mongo-express package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Cross-Site Request Forgery (CSRF)

    mongo-express is a web-based MongoDB admin interface written with Node.js, Express and Bootstrap3

    Affected versions of this package are vulnerable to Cross-Site Request Forgery (CSRF) due to insufficient protection on the /admin endpoint. An attacker can perform unauthorized actions on behalf of a logged-in user by tricking them into clicking a malicious link or visiting a crafted webpage.

    How to fix Cross-Site Request Forgery (CSRF)?

    Upgrade mongo-express to version 1.1.0-rc-1 or higher.

    <1.1.0-rc-1