'; } else{ echo ''; } echo '
|
|||
Release Date:2025/9/15
Rule Name:Yapi NoSQL Injection Vulnerability
Severity:high
CVE ID:
Descripiton:
|
YMFE Yapi is a visual interface management platform from YMFE Corporation. Yapi which in the version prior to v1.12.0, are vulnerable to a NoSQL injection, as well as a remote code execution vulnerability. The remote attacker could steal project's token through NoSQL injection without authentication and use this token to execute the Mock script and get shell. This rule is used to detect the suspicious behavior of obtaining the item Token through the Nosal vulnerability.This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
Solution:
|
Update vendor patches.