mongo-express before 0.54.0 is vulnerable to remote code execution via endpoints that uses the toBSON
method and misuse the vm
dependency to perform exec
commands in a non-safe environment.
View the template here CVE-2019-10758.yaml
References:
https://github.com/vulhub/vulhub/tree/master/mongo-express/CVE-2019-10758