WhisperX tag archive

#NoSQL Injection

This page collects WhisperX intelligence signals tagged #NoSQL Injection. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (3)

The Lab · 2026-04-19 08:22:33 · GitHub Issues

2. Critical Security Flaw: Plaintext Passwords & NoSQL Injection Expose Full User Database

A critical vulnerability in a web application's authentication stack allows unauthenticated remote attackers to bypass login entirely and harvest every user's credentials in plaintext. The flaw, rated a maximum CVSS score of 9.8, stems from two root-cause issues in the codebase: plaintext password storage and a NoSQL i...

The Lab · 2026-04-19 08:22:36 · GitHub Issues

3. Critical NoSQL Injection in user-dao.js Exposes Authentication Bypass (CVSS 9.8)

A critical NoSQL injection vulnerability in a core authentication function allows unauthenticated attackers to bypass login controls and potentially gain administrative access. The flaw, rated a maximum CVSS score of 9.8, resides in the `validateLogin()` function within the `app/data/user-dao.js` file. It passes the ra...