itsKedar / TodoList_mern

0 stars 0 forks source link

CX MongoDB_NoSQL_Injection @ server/server.js [main] #32

Open itsKedar opened 1 year ago

itsKedar commented 1 year ago

MongoDB_NoSQL_Injection issue exists @ server/server.js in branch main

The application relies on user inputs provided in complete in server\server.js at line 49 to construct a raw MongoDB query with CxAssociativeArray_95b444c4 in server\server.js at line 48.

Severity: High

CWE:89

Checkmarx

Training Recommended Fix

Lines: 49


Code (Line #49):

    complete: req.body.complete,

itsKedar commented 3 weeks ago

critical