You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I jumped the gun on creating this issue. The successful exploitation of this vulnerability requires knowledge of a specific vulnerable endpoint. In the PoC's test application the endpoint /v1/user is configured to be vulnerable however in real world applications the user would first have to find a vulnerable endpoint via whitebox analysis or some prior knowledge, making this a non-ideal candidate for a metasploit module.
Summary
This module will exploit a SpEL injection vulnerability in Spring Data MongoDB
Basic example
https://github.com/kuron3k0/Spring-Data-Mongodb-Example
The text was updated successfully, but these errors were encountered: