ZERO
Back
attack-patternCAPEC-676

NoSQL Injection

An adversary targets software that constructs NoSQL statements based on user input or with parameters vulnerable to operator replacement in order to achieve a variety of technical impacts such as escalating privileges, bypassing authentication, and/or executing code.

Typical severity
High
Likelihood of attack
High

Classification

Summary

Details

Prerequisites

Summary

Details

Execution flow

Summary

Details