Web Hack List

Collected research

MongoDB NoSQL Injection with Aggregation Pipelines

An application that passes user input into MongoDB's aggregation stage lets NoSQL injection escape the single collection a find would confine it to: lookup and union stages read other collections such as users, while replace and merge stages write to them. An attacker can dump credentials, insert a new admin account, or overwrite an existing user's password and role.

Record

Researcher
Soroush Dalili
Published by
soroush.me
Topic
Injection

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Soroush Dalili, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .