云虫漏洞情报

CVE-2026-76794 - MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before including it in generated HTML. A MongoDB user with write access can introduce crafted metadata that may cause script code to run when another user generates and opens the report, potentially exposing report contents or altering its display. - 漏洞详情

漏洞编号:CVE-2026-76794

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-76794

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-79

发布/更新时间:2026-08-28 / 2026-08-28

漏洞描述

MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before including it in generated HTML. A MongoDB user with write access can introduce crafted metadata that may cause script code to run when another user generates and opens the report, potentially exposing report contents or altering its display.

相关链接

相关漏洞

« 返回首页