QID 981012
QID 981012: Nodejs (npm) Security Update for flintcms (GHSA-jhq3-57xh-6643)
Versions of `flintcms` before version 1.1.10 are vulnerable to account takeover due to blind MongoDB injection in the password reset.
## Recommendation
Update to version 1.1.10 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-jhq3-57xh-6643 for updates pertaining to this vulnerability.
Vendor References
- GHSA-jhq3-57xh-6643 -
github.com/advisories/GHSA-jhq3-57xh-6643
CVEs related to QID 981012
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-jhq3-57xh-6643 | flintcms |
|