attack-patternCAPEC-676
NoSQL Injection
An adversary targets software that constructs NoSQL statements based on user input or with parameters vulnerable to operator replacement in order to achieve a variety of technical impacts such as escalating privileges, bypassing authentication, and/or executing code.
Typical severity
High
Likelihood of attack
High
Classification
Summary
Details
Prerequisites
Summary
Details
Execution flow
Summary
Details