A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.
PoC: Spring-Data-Mongodb-Demo
CVE-2022-22980环境
PoC: Spring_cve-2022-22980
spring data mongodb remote code execution | cve-2022-22980 poc
PoC: CVE-2022-22980
Exploitation de CVE-2022-22980 sur HTB
PoC: cve-2022-22980-exp
CVE-2022-22980 exp demp可作为扫描器靶场
PoC: CVE-2022-22980
Poc of CVE-2022-22980
PoC: CVE-2022-22980
[CVE-2022-22980] Spring Data MongoDB SpEL Expression injection
PoC: Spring-Data-Mongodb-Example
CVE-2022-22980环境
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free