CAPEC 676 NoSQL Injection

Stable Standard High Risk
Severity High

Description

{'xhtml:p': 'An adversary targets software that constructs NoSQL statements based on user input or with parameters vulnerable to operator replacement in order to achieve a variety of technical impacts such as escalating privileges, bypassing authentication, and/or executing code.'}

Attack Execution Flow

4

Mitigations

8

Consequences

Indicators

2

Relationships

Resources Required

1