Showing 2 vulnerabilities on this page for MongoDB PHP Driver

Signals CISA KEV Ransomware Nuclei
MongoDB Inc vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Accessing Untrusted Directory May Allow Local Privilege Escalation

Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour determined by the contents of untrusted files. This issue affects MongoDB Server v5.0 versions prior to 5.0.27, MongoDB Server v6.0 versions prior to 6.0.16, MongoDB Server v7.0 versions prior to 7.0.12, MongoDB Server v7.3 versions prior 7.3.3, MongoDB C Driver versions prior to

CWE-284Aug 7, 2024
CVSS7.3v3.1EPSS0.26%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Some MongoDB Drivers may publish events containing authentication-related data to a command listener configured by an application

Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This

CWE-200CWE-532Aug 29, 2023
CVSS4.2v3.1EPSS0.596%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX