Impact
Improper neutralization of query operators in the embedded‑document relation handling allows a caller to supply an identifier that is interpreted as a filter condition. An authenticated user who can influence such an identifier can either delete every embedded document within a target record or overwrite a different embedded document, resulting in significant data loss or corruption. The weakness is classified as CWE‑943.
Affected Systems
MongoDB integration for Laravel (PHP). No specific product version information is provided; the vulnerability exists in any affected release of the MongoDB Laravel driver where the identifier is not properly checked.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high severity, and the EPSS score is not available, suggesting limited publicly available exploitation data. The vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated with write privileges to the target record; thus, the threat surface is confined to users with sufficient access. Once an attacker meets this prerequisite, they can directly manipulate the database through the application’s API without needing additional network or privilege escalation steps.
OpenCVE Enrichment