Skip to main content

Vendor/product archive

steedos / steedos CVEs

Beta · best-effort

1 CVEs tagged to steedos / steedos0 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2020-35666

Published Dec 23, 2020

Steedos Platform through 1.21.24 allows NoSQL injection because the /api/collection/findone implementation in server/packages/steedos_base.js mishandles req.body validation, as de…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-1 of 1 CVEsPage 1 of 1