Impact
An improper neutralization of special elements in the GridFS component of the MongoDB C Driver allows an attacker to supply a file identifier that is interpreted as a query condition instead of a literal value. An attacker who can influence the identifier may read files beyond the intended target or delete all GridFS file chunks in a bucket, effectively destroying stored data.
Affected Systems
The vulnerability affects applications that use the MongoDB C Driver, specifically the GridFS component, regardless of the vendor’s base product. No specific driver version information is provided.
Risk and Exploitability
The CVSS score is 6.1, indicating moderate severity, and the vulnerability is not listed in the CISA KEV catalog. Although the description does not explicity state the required access level, it is inferred that an authenticated user who can control the file identifier can exploit the flaw. Exploitation would involve crafting a malicious identifier to manipulate query logic, leading to data exposure or deletion.
OpenCVE Enrichment