{"id":17819,"date":"2021-11-16T12:22:24","date_gmt":"2021-11-16T06:52:24","guid":{"rendered":"https:\/\/www.varutra.com\/?p=17819"},"modified":"2022-12-02T11:39:11","modified_gmt":"2022-12-02T06:09:11","slug":"nosql-injection-vulnerability","status":"publish","type":"post","link":"https:\/\/www.varutra.com\/varutravrt3\/nosql-injection-vulnerability\/","title":{"rendered":"NoSQL Injection Vulnerability"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" width=\"1920\" height=\"1080\" src=\"https:\/\/varutra-1a3b6.kxcdn.com\/wp-content\/uploads\/2021\/11\/MicrosoftTeams-image-1024x535.png\"  class=\"sh-overlay-item sh-table-cell ls-is-cached lazyloaded\" data-rel=\"lightcase\" title=\"NoSQL Injection Vulnerability - Varutra Consulting\"><br \/>\nIn this blog, we will be discussing the NoSQL Injection Vulnerability and its exploitations scenarios.<\/p>\n<p>Before getting into the details of NoSQL injections, let us first see the difference between SQL (Structured Query Language) and NoSQL (Not Only Structured Query Language) databases.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17820 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/11\/Comparison-between-sql-and-no-sql.png\" alt=\"Comparison between sql and no sql\" width=\"633\" height=\"319\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/11\/Comparison-between-sql-and-no-sql.png 633w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/11\/Comparison-between-sql-and-no-sql-300x151.png 300w\" sizes=\"(max-width: 633px) 100vw, 633px\" \/><br \/>\nThere are multiple NoSQL databases available in the market, such as<\/p>\n<ul>\n<li>Mongo DB<\/li>\n<li>Elastic Search<\/li>\n<li>AmazonDynamoDB<\/li>\n<li>HBase<\/li>\n<li>Cassandra, etc.<\/li>\n<\/ul>\n<p>Mongo DB stores the document in a JSON object (JavaScript object notation), mainly used for document databases.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong><u>What is NoSQL Injection Vulnerability? <\/u><\/strong><\/h3>\n<p>The NoSQL injection is a vulnerability that occurs due to improper input validation. It allows attacker users to view or change backend data to which they do not have access. It happens at the application layer, and successfully exploiting this vulnerability could allow an attacker to gain full access to the data present in the database. Also, an attacker could run malicious queries, which could hamper confidentiality, integrity, and availability of data present in the database.<\/p>\n<p>Now let us explore NoSQL injection in detail. NoSQL injection vulnerability is much similar to the traditional <a href=\"https:\/\/www.varutra.com\/varutrapreprod\/second-order-sql-injection-attack\/\">SQL injection vulnerability<\/a>.<\/p>\n<p>NoSQL databases were created to eliminate SQL injection problems in SQL databases and were considered highly secure compared to SQL databases. However, an injection is still possible in the case of NoSQL databases due to misconfiguration and loopholes left open during the development phase. In this blog, we will be focusing specifically on Mongo DB.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong><u>Commonly used operators in NoSQL Injection Vulnerability<\/u><\/strong><\/h3>\n<ol>\n<li><strong>$ne<\/strong> = Not equal to<\/li>\n<li><strong>$eq<\/strong> = Equal to<\/li>\n<li><strong>$gt<\/strong> = Greater than<\/li>\n<li><strong>$lt<\/strong> = Less than<\/li>\n<li><strong>$regex<\/strong> = Regular expression<\/li>\n<li><strong>$in<\/strong> = Check if the required data is present in a data structure such as an array, etc.<\/li>\n<\/ol>\n<p>Below mentioned is an example of the simple query used for the authentication process in Mongo DB.<\/p>\n<pre><em><strong>db.user_auth.find({Username: username, Password: password});<\/strong><\/em><\/pre>\n<p>The query shown above is used for authenticating a user. In this query, user input such as username and password is directly used without input validation, thus allowing an attacker to inject data structures such as arrays, etc., mongo DB operators instead of a valid username and password. This data is either sent using JSON object or URL parameter.<\/p>\n<p>Below shown is the expected JSON object by the application:<\/p>\n<pre><em><strong>{ Username: \u201cusername\u201d, Password: \u201dpassword\u201d }<\/strong><\/em><\/pre>\n<p>JSON object after injecting authentication bypass NoSQL payloads:<\/p>\n<pre><em><strong>{ Username: { $ne: \u201d\u201d }, Password: { $ne: \u201d\u201d } }<\/strong><\/em><\/pre>\n<p>Request to the mongo DB could be sent in two ways:<\/p>\n<ol>\n<li><strong>Using form URL encoding schema<\/strong><\/li>\n<\/ol>\n<p>In this case, the payload is injected along with parameter names within a data structure like an array containing operators inside it.<\/p>\n<p>Example:<\/p>\n<pre><em><strong>POST \/login HTTP\/1.1 <\/strong><\/em>\r\n<em><strong>Host: target.com <\/strong><\/em><em><strong>Content-Type: application\/x-www-form-urlencoded<\/strong><\/em>\r\n<em><strong>Content-Length: 27\r\n <\/strong><\/em>\r\n<em><strong>user=admin&amp;password[$ne]=<\/strong><\/em><\/pre>\n<ol start=\"2\">\n<li><strong>Using JSON object<\/strong><\/li>\n<\/ol>\n<p>In the case of a JSON object, a payload can be inserted directly into the value field.<\/p>\n<p>Example:<\/p>\n<pre><em><strong>POST \/login HTTP\/1.1 <\/strong><\/em>\r\n<em><strong>Host: target.com <\/strong><\/em>\r\n<em><strong>Content-Type: application\/json <\/strong><\/em>\r\n<em><strong>Content-Length: 38\u00a0<\/strong><\/em>\r\n\r\n<em><strong>{<\/strong><\/em>\r\n<em><strong>\u201cusername\u201d: \u201cadmin\u201d,<\/strong><\/em>\r\n<em><strong>\u201cPassword\u201d: {'$ne': \u201c\u201d}<\/strong><\/em>\r\n\r\n<em><strong>}\r\n\r\n<\/strong><\/em><\/pre>\n<h3><strong><u>Common NoSQL Injection Attack Scenarios:<\/u><\/strong><\/h3>\n<ol>\n<li><strong>Data exfiltration<\/strong><\/li>\n<\/ol>\n<p>Data such as username, password, secrets, etc., could be easily gathered using the <strong>$regex<\/strong> operator.<\/p>\n<p><strong>$regex<\/strong> operator makes use of regular expression using which an attacker could quickly check the length of the data, check if the data starts with a particular character, etc.<\/p>\n<p>Example: In this case, <strong>$regex<\/strong> is used to guess the find the length of the password if the username is admin.<\/p>\n<pre><em><strong>POST \/login HTTP\/1.1 <\/strong><\/em>\r\n<em><strong>Host: target.com <\/strong><\/em>\r\n<em><strong>Content-Type: application\/x-www-form-urlencoded <\/strong><\/em>\r\n<em><strong>Content-Length: 27<\/strong><\/em>\r\n\r\n<em><strong>username[$ne]=admin&amp;password[$regex]=.{5}\u00a0<\/strong><\/em><\/pre>\n<ol start=\"2\">\n<li><strong>Authentication Bypass<\/strong><\/li>\n<\/ol>\n<p>Below shown is the simple authentication bypass scenario in which the application is vulnerable to NoSQL injection.<\/p>\n<p>The username is admin, and instead of a password, we are sending JSON object with\u00a0<strong>$ne<\/strong>\u00a0operator.\u00a0<strong>$ne<\/strong>\u00a0will return true since the password value is not null.<\/p>\n<pre><em><strong>POST \/login HTTP\/1.1 <\/strong><\/em>\r\n<em><strong>Host: target.com <\/strong><\/em>\r\n<em><strong>Content-Type: application\/json <\/strong><\/em>\r\n<em><strong>Content-Length: 38\u00a0<\/strong><\/em>\r\n\r\n<em><strong>{\"username\":\"admin\", \"password\": {\"$ne\": null}}<\/strong><\/em><\/pre>\n<ol start=\"3\">\n<li><strong>Denial of Service Attack<\/strong><\/li>\n<\/ol>\n<p>In the backend\u00a0<strong>$where<\/strong>\u00a0the operator is used, injecting JavaScript code having infinite while loop as a user-supplied data will result in total CPU power consumption.<\/p>\n<p>For more payloads for exploitation of NoSQL injection vulnerability, do check out this\u00a0<a href=\"https:\/\/github.com\/swisskyrepo\/PayloadsAllTheThings\/tree\/master\/NoSQL%20Injection\">link<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong><u>Automated tools available for detecting and exploiting NoSQL injection vulnerability<\/u><\/strong><\/h3>\n<ul>\n<li><strong>NoSQLMap\u00a0<\/strong><\/li>\n<\/ul>\n<p><a href=\"https:\/\/github.com\/codingo\/NoSQLMap\">NoSQLMap<\/a>\u00a0is an open-source python tool designed for auditing and automating injection attacks. However, there is a default configuration weakness in NoSQL databases and web applications that can be exploited. This procedure is carried out by using NoSQL to clone data or disclose it from the database.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong><u>Demonstration of simple attack scenario by exploiting NoSQL injection vulnerability<\/u><\/strong><\/h3>\n<p>For the demo purpose, we will be making use of the OWASP juice shop application. In this application, after the authentication, the user is allowed to submit a review for a product. Once the review is submitted, a user only has permission to edit his review, not the other reviews given by other users in the application. For example, in this application, the user has the email id\u00a0<a href=\"mailto:&#x74;&#x65;&#x73;&#x74;&#x40;&#x74;&#x65;&#x73;&#x74;&#x2e;&#x63;&#x6f;&#x6d;\">&#x74;&#x65;&#x73;&#x74;&#x40;<span class=\"oe_displaynone\">null<\/span>&#x74;&#x65;&#x73;&#x74;&#x2e;&#x63;&#x6f;&#x6d;<\/a>.<\/p>\n<ul>\n<li style=\"text-align: left\">The user clicks on a product and submits the review, as shown below.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-17825 size-full\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/11\/POC-User-submits-a-review.jpg\" alt=\"POC - User submits a review (NoSQL Injection Vulnerability)\" width=\"1210\" height=\"761\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/11\/POC-User-submits-a-review.jpg 1210w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/11\/POC-User-submits-a-review-300x189.jpg 300w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/11\/POC-User-submits-a-review-1024x644.jpg 1024w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/11\/POC-User-submits-a-review-768x483.jpg 768w\" sizes=\"(max-width: 1210px) 100vw, 1210px\" \/><\/p>\n<p style=\"text-align: center\"><strong>POC: User submits a review<\/strong><\/p>\n<ul>\n<li>After submitting it, the user clicks on edit the make changes in the proposed review.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17824 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/11\/POC-Edit-submitted-review-and-intercept-the-request.jpg\" alt=\"POC - Edit submitted review and intercept the request\" width=\"1249\" height=\"774\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/11\/POC-Edit-submitted-review-and-intercept-the-request.jpg 1249w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/11\/POC-Edit-submitted-review-and-intercept-the-request-300x186.jpg 300w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/11\/POC-Edit-submitted-review-and-intercept-the-request-1024x635.jpg 1024w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/11\/POC-Edit-submitted-review-and-intercept-the-request-768x476.jpg 768w\" sizes=\"(max-width: 1249px) 100vw, 1249px\" \/><\/p>\n<p style=\"text-align: center\"><strong>POC: Edit submitted a review and intercept the request<\/strong><\/p>\n<ul>\n<li>Intercept the request after editing the review. Each review has a unique alphanumeric ID value.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17828 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/11\/POC-Intercept-the-edit-request-1.jpg\" alt=\"POC - Intercept the edit request\" width=\"802\" height=\"502\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/11\/POC-Intercept-the-edit-request-1.jpg 802w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/11\/POC-Intercept-the-edit-request-1-300x188.jpg 300w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/11\/POC-Intercept-the-edit-request-1-768x481.jpg 768w\" sizes=\"(max-width: 802px) 100vw, 802px\" \/><\/p>\n<p style=\"text-align: center\"><strong>POC: Intercept the edit request<\/strong><\/p>\n<ul>\n<li>Remove the Id parameter and add a simple NoSQL injection payload. It will ensure that the ID supplied is not equal to the ID value specified, i.e., -1.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17822 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/11\/POC-Added-NoSQL-injection-payload-in-id-parameter.jpg\" alt=\"POC - Added NoSQL injection payload in id parameter\" width=\"1519\" height=\"719\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/11\/POC-Added-NoSQL-injection-payload-in-id-parameter.jpg 1519w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/11\/POC-Added-NoSQL-injection-payload-in-id-parameter-300x142.jpg 300w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/11\/POC-Added-NoSQL-injection-payload-in-id-parameter-1024x485.jpg 1024w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/11\/POC-Added-NoSQL-injection-payload-in-id-parameter-768x364.jpg 768w\" sizes=\"(max-width: 1519px) 100vw, 1519px\" \/><\/p>\n<p style=\"text-align: center\"><strong>POC: Added NoSQL injection payload in the id parameter<\/strong><\/p>\n<ul>\n<li>Refresh the web page. NoSQL injection payload executes and alters all the reviews submitted by all the users.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17821 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/11\/POC-All-the-submitted-review-changed-to-attacker-supplied-review-text.jpg\" alt=\"POC - All the submitted review changed to attacker supplied review text\" width=\"1258\" height=\"763\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/11\/POC-All-the-submitted-review-changed-to-attacker-supplied-review-text.jpg 1258w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/11\/POC-All-the-submitted-review-changed-to-attacker-supplied-review-text-300x182.jpg 300w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/11\/POC-All-the-submitted-review-changed-to-attacker-supplied-review-text-1024x621.jpg 1024w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/11\/POC-All-the-submitted-review-changed-to-attacker-supplied-review-text-768x466.jpg 768w\" sizes=\"(max-width: 1258px) 100vw, 1258px\" \/><\/p>\n<p style=\"text-align: center\"><strong>POC: All the submitted reviews changed to attacker-supplied review text<\/strong><\/p>\n<p>&nbsp;<\/p>\n<h3><strong><u>Mitigation<\/u><\/strong><\/h3>\n<ul>\n<li>User data must be validated appropriately by identifying malicious data, such as objects and arrays used to inject NoSQL databases to prevent NoSQL injection.<\/li>\n<li>Lastly, admins and developers need to consider the access rights that must be afforded to the applications. A wrong decision can mitigate the potential damage of NoSQL injection attacks or any other attacks.<\/li>\n<li>In mongo DB, don\u2019t use\u00a0<strong>where<\/strong>,\u00a0<strong>MapReduce<\/strong>, or\u00a0<strong>group<\/strong>\u00a0operators with user input, because these operators allow the attacker to inject JavaScript, and the result can be dangerous.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3><strong><u>Conclusion:<\/u><\/strong><\/h3>\n<p>Attackers can now not only extract the data from the database but also execute code in the application. For example, perform denial of service attacks or even take control of the user\u2019s system or server. These attacks are pretty dangerous as the developers often use NoSQL data stores for relational database products, increasing the risk of insecure codes. Therefore, the most optimum way to reduce the dangers of NoSQL attacks is to avoid using uncertain user inputs in the application code.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong><u>References:<\/u><\/strong><\/h3>\n<ul>\n<li><a href=\"https:\/\/blog.websecurify.com\/2014\/08\/hacking-nodejs-and-mongodb.html\">https:\/\/blog.websecurify.com\/2014\/08\/hacking-nodejs-and-mongodb.html<\/a><\/li>\n<li><a href=\"https:\/\/blog.websecurify.com\/2014\/08\/attacks-nodejs-and-mongodb-part-to.html\">https:\/\/blog.websecurify.com\/2014\/08\/attacks-nodejs-and-mongodb-part-to.html<\/a><\/li>\n<li><a href=\"https:\/\/owasp.org\/www-project-web-security-testing-guide\/v42\/4-Web_Application_Security_Testing\/07-Input_Validation_Testing\/05.6-Testing_for_NoSQL_Injection.html\">https:\/\/owasp.org\/www-project-web-security-testing-guide\/v42\/4-Web_Application_Security_Testing\/07-Input_Validation_Testing\/05.6-Testing_for_NoSQL_Injection.html<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>Author,<\/p>\n<p><strong>Gaurish Kauthankar<\/strong><\/p>\n<p>Attack &amp; PenTest Team<\/p>\n<p>Varutra Consulting Pvt. Ltd.<\/p>","protected":false},"excerpt":{"rendered":"<p>In this blog, we will be discussing the NoSQL Injection Vulnerability and its exploitations scenarios. Before getting into the details of NoSQL injections, let us&#8230;<\/p>\n","protected":false},"author":4,"featured_media":17826,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[57,272],"tags":[554,552,553],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 4.9.10 - aioseo.com -->\n\t<meta name=\"description\" content=\"NoSQL injection vulnerability permits the user to inject malicious code into the command database that doesn\u2019t use SQL queries. For example, MongoDB.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"kalpblogger\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.varutra.com\/varutravrt3\/nosql-injection-vulnerability\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 4.9.10\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Varutra Consulting\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"NoSQL Injection Vulnerability &amp; Its Exploitations Scenarios\" \/>\n\t\t<meta property=\"og:description\" content=\"NoSQL injection vulnerability permits the user to inject malicious code into the command database that doesn\u2019t use SQL queries. For example, MongoDB.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.varutra.com\/varutravrt3\/nosql-injection-vulnerability\/\" \/>\n\t\t<meta property=\"article:tag\" content=\"nosql database exploitation\" \/>\n\t\t<meta property=\"article:tag\" content=\"nosql injection\" \/>\n\t\t<meta property=\"article:tag\" content=\"nosql vulnerability\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-11-16T06:52:24+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-12-02T06:09:11+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"NoSQL Injection Vulnerability &amp; Its Exploitations Scenarios\" \/>\n\t\t<meta name=\"twitter:description\" content=\"NoSQL injection vulnerability permits the user to inject malicious code into the command database that doesn\u2019t use SQL queries. For example, MongoDB.\" \/>\n\t\t<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t\t<meta name=\"twitter:data1\" content=\"kalpblogger\" \/>\n\t\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/nosql-injection-vulnerability\\\/#article\",\"name\":\"NoSQL Injection Vulnerability & Its Exploitations Scenarios\",\"headline\":\"NoSQL Injection Vulnerability\",\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/MicrosoftTeams-image.png\",\"width\":1200,\"height\":627,\"caption\":\"NoSQL Injection Vulnerability\"},\"datePublished\":\"2021-11-16T12:22:24+05:30\",\"dateModified\":\"2022-12-02T11:39:11+05:30\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/nosql-injection-vulnerability\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/nosql-injection-vulnerability\\\/#webpage\"},\"articleSection\":\"Vulnerability Disclosure, Web Application Security, NoSQL Database Exploitation, NoSQL Injection, NoSQL Vulnerability\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/nosql-injection-vulnerability\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/vulnerability-disclosure\\\/#listItem\",\"name\":\"Vulnerability Disclosure\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/vulnerability-disclosure\\\/#listItem\",\"position\":2,\"name\":\"Vulnerability Disclosure\",\"item\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/vulnerability-disclosure\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/nosql-injection-vulnerability\\\/#listItem\",\"name\":\"NoSQL Injection Vulnerability\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/nosql-injection-vulnerability\\\/#listItem\",\"position\":3,\"name\":\"NoSQL Injection Vulnerability\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/vulnerability-disclosure\\\/#listItem\",\"name\":\"Vulnerability Disclosure\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\",\"name\":\"Varutra\",\"description\":\"Secure your digital world with our Cybersecurity services.\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/Varutra-Found-e1612984024606.jpg\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/nosql-injection-vulnerability\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/nosql-injection-vulnerability\\\/#organizationLogo\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/\",\"name\":\"kalpblogger\",\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/5e96a9b330da7c941c1e39217a2fbe38?s=96&d=mm&r=g\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/nosql-injection-vulnerability\\\/#webpage\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/nosql-injection-vulnerability\\\/\",\"name\":\"NoSQL Injection Vulnerability & Its Exploitations Scenarios\",\"description\":\"NoSQL injection vulnerability permits the user to inject malicious code into the command database that doesn\\u2019t use SQL queries. For example, MongoDB.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/nosql-injection-vulnerability\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/MicrosoftTeams-image.png\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/nosql-injection-vulnerability\\\/#mainImage\",\"width\":1200,\"height\":627,\"caption\":\"NoSQL Injection Vulnerability\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/nosql-injection-vulnerability\\\/#mainImage\"},\"datePublished\":\"2021-11-16T12:22:24+05:30\",\"dateModified\":\"2022-12-02T11:39:11+05:30\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"name\":\"Varutra Consulting\",\"description\":\"Secure your digital world with our Cybersecurity services.\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>NoSQL Injection Vulnerability &amp; Its Exploitations Scenarios<\/title>\n\n","aioseo_head_json":{"title":"NoSQL Injection Vulnerability & Its Exploitations Scenarios","description":"NoSQL injection vulnerability permits the user to inject malicious code into the command database that doesn\u2019t use SQL queries. For example, MongoDB.","canonical_url":"https:\/\/www.varutra.com\/varutravrt3\/nosql-injection-vulnerability\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.varutra.com\/varutravrt3\/nosql-injection-vulnerability\/#article","name":"NoSQL Injection Vulnerability & Its Exploitations Scenarios","headline":"NoSQL Injection Vulnerability","author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author"},"publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/11\/MicrosoftTeams-image.png","width":1200,"height":627,"caption":"NoSQL Injection Vulnerability"},"datePublished":"2021-11-16T12:22:24+05:30","dateModified":"2022-12-02T11:39:11+05:30","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/nosql-injection-vulnerability\/#webpage"},"isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/nosql-injection-vulnerability\/#webpage"},"articleSection":"Vulnerability Disclosure, Web Application Security, NoSQL Database Exploitation, NoSQL Injection, NoSQL Vulnerability"},{"@type":"BreadcrumbList","@id":"https:\/\/www.varutra.com\/varutravrt3\/nosql-injection-vulnerability\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3#listItem","position":1,"name":"Home","item":"https:\/\/www.varutra.com\/varutravrt3","nextItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/category\/vulnerability-disclosure\/#listItem","name":"Vulnerability Disclosure"}},{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/category\/vulnerability-disclosure\/#listItem","position":2,"name":"Vulnerability Disclosure","item":"https:\/\/www.varutra.com\/varutravrt3\/category\/vulnerability-disclosure\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/nosql-injection-vulnerability\/#listItem","name":"NoSQL Injection Vulnerability"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/nosql-injection-vulnerability\/#listItem","position":3,"name":"NoSQL Injection Vulnerability","previousItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/category\/vulnerability-disclosure\/#listItem","name":"Vulnerability Disclosure"}}]},{"@type":"Organization","@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization","name":"Varutra","description":"Secure your digital world with our Cybersecurity services.","url":"https:\/\/www.varutra.com\/varutravrt3\/","logo":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/11\/Varutra-Found-e1612984024606.jpg","@id":"https:\/\/www.varutra.com\/varutravrt3\/nosql-injection-vulnerability\/#organizationLogo"},"image":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/nosql-injection-vulnerability\/#organizationLogo"}},{"@type":"Person","@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author","url":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/","name":"kalpblogger","image":{"@type":"ImageObject","url":"https:\/\/secure.gravatar.com\/avatar\/5e96a9b330da7c941c1e39217a2fbe38?s=96&d=mm&r=g"}},{"@type":"WebPage","@id":"https:\/\/www.varutra.com\/varutravrt3\/nosql-injection-vulnerability\/#webpage","url":"https:\/\/www.varutra.com\/varutravrt3\/nosql-injection-vulnerability\/","name":"NoSQL Injection Vulnerability & Its Exploitations Scenarios","description":"NoSQL injection vulnerability permits the user to inject malicious code into the command database that doesn\u2019t use SQL queries. For example, MongoDB.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#website"},"breadcrumb":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/nosql-injection-vulnerability\/#breadcrumblist"},"author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author"},"creator":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/11\/MicrosoftTeams-image.png","@id":"https:\/\/www.varutra.com\/varutravrt3\/nosql-injection-vulnerability\/#mainImage","width":1200,"height":627,"caption":"NoSQL Injection Vulnerability"},"primaryImageOfPage":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/nosql-injection-vulnerability\/#mainImage"},"datePublished":"2021-11-16T12:22:24+05:30","dateModified":"2022-12-02T11:39:11+05:30"},{"@type":"WebSite","@id":"https:\/\/www.varutra.com\/varutravrt3\/#website","url":"https:\/\/www.varutra.com\/varutravrt3\/","name":"Varutra Consulting","description":"Secure your digital world with our Cybersecurity services.","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"}}]},"og:locale":"en_US","og:site_name":"Varutra Consulting","og:type":"article","og:title":"NoSQL Injection Vulnerability &amp; Its Exploitations Scenarios","og:description":"NoSQL injection vulnerability permits the user to inject malicious code into the command database that doesn\u2019t use SQL queries. For example, MongoDB.","og:url":"https:\/\/www.varutra.com\/varutravrt3\/nosql-injection-vulnerability\/","article:tag":["nosql database exploitation","nosql injection","nosql vulnerability"],"article:published_time":"2021-11-16T06:52:24+00:00","article:modified_time":"2022-12-02T06:09:11+00:00","twitter:card":"summary_large_image","twitter:title":"NoSQL Injection Vulnerability &amp; Its Exploitations Scenarios","twitter:description":"NoSQL injection vulnerability permits the user to inject malicious code into the command database that doesn\u2019t use SQL queries. For example, MongoDB.","twitter:label1":"Written by","twitter:data1":"kalpblogger","twitter:label2":"Est. reading time","twitter:data2":"6 minutes"},"aioseo_meta_data":{"post_id":"17819","title":"NoSQL Injection Vulnerability &amp; Its Exploitations Scenarios","description":"NoSQL injection vulnerability permits the user to inject malicious code into the command database that doesn\u2019t use SQL queries. For example, MongoDB.","keywords":[],"keyphrases":{"focus":{"keyphrase":"NoSQL Injection Vulnerability","score":90,"analysis":{"keyphraseInTitle":{"title":"Focus keyphrase in SEO title","description":"Focus keyphrase found in SEO title.","score":9,"maxScore":9,"error":0},"keyphraseInDescription":{"title":"Focus keyphrase in meta description","description":"Focus keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseLength":{"title":"Focus keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":3},"keyphraseInURL":{"title":"Focus keyphrase in URL","description":"Focus keyphrase used in the URL.","score":5,"maxScore":5,"error":0},"keyphraseInIntroduction":{"title":"Focus keyphrase in introduction","description":"Your Focus keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.","score":3,"maxScore":9,"error":1},"keyphraseInSubHeadings":{"title":"Focus keyphrase in Subheadings","description":"Your H2 and H3 subheadings reflects the topic of your copy. Good job!","score":9,"maxScore":9,"error":0},"keyphraseInImageAlt":{"title":"Focus keyphrase in image alt attributes","description":"Focus keyphrase found in image alt attribute(s).","score":9,"maxScore":9,"error":0}}},"additional":[{"keyphrase":"NoSQL Injection","score":83,"analysis":{"keyphraseInDescription":{"title":"Keyphrase in meta description","description":"Keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseLength":{"title":"Keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":2},"keyphraseInIntroduction":{"title":"Keyphrase in introduction","description":"Your Keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.","score":3,"maxScore":9,"error":1},"keyphraseInImageAlt":{"title":"Keyphrase in image alt attributes","description":"Keyphrase found in image alt attribute(s).","score":9,"maxScore":9,"error":0}}},{"keyphrase":"NoSQL","score":83,"analysis":{"keyphraseInDescription":{"title":"Keyphrase in meta description","description":"Keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseLength":{"title":"Keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":1},"keyphraseInIntroduction":{"title":"Keyphrase in introduction","description":"Your Keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.","score":3,"maxScore":9,"error":1},"keyphraseInImageAlt":{"title":"Keyphrase in image alt attributes","description":"Keyphrase found in image alt attribute(s).","score":9,"maxScore":9,"error":0}}},{"keyphrase":"Vulnerability","score":83,"analysis":{"keyphraseInDescription":{"title":"Keyphrase in meta description","description":"Keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseLength":{"title":"Keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":1},"keyphraseInIntroduction":{"title":"Keyphrase in introduction","description":"Your Keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.","score":3,"maxScore":9,"error":1},"keyphraseInImageAlt":{"title":"Keyphrase in image alt attributes","description":"Keyphrase found in image alt attribute(s).","score":9,"maxScore":9,"error":0}}}]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":[],"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":"{\"article\":{\"articleType\":\"BlogPosting\"},\"course\":{\"name\":\"\",\"description\":\"\",\"provider\":\"\"},\"faq\":{\"pages\":[]},\"product\":{\"reviews\":[]},\"recipe\":{\"ingredients\":[],\"instructions\":[],\"keywords\":[]},\"software\":{\"reviews\":[],\"operatingSystems\":[]},\"webPage\":{\"webPageType\":\"WebPage\"}}","pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"limit_modified_date":false,"reviewed_by":null,"open_ai":null,"created":"2021-11-16 06:45:08","updated":"2026-05-24 10:00:46","ai":null,"breadcrumb_settings":null,"seo_analyzer_scan_date":"2026-05-22 13:55:12"},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\/category\/vulnerability-disclosure\/\" title=\"Vulnerability Disclosure\">Vulnerability Disclosure<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tNoSQL Injection Vulnerability\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.varutra.com\/varutravrt3"},{"label":"Vulnerability Disclosure","link":"https:\/\/www.varutra.com\/varutravrt3\/category\/vulnerability-disclosure\/"},{"label":"NoSQL Injection Vulnerability","link":"https:\/\/www.varutra.com\/varutravrt3\/nosql-injection-vulnerability\/"}],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/17819"}],"collection":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/comments?post=17819"}],"version-history":[{"count":4,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/17819\/revisions"}],"predecessor-version":[{"id":20229,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/17819\/revisions\/20229"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/media\/17826"}],"wp:attachment":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/media?parent=17819"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/categories?post=17819"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/tags?post=17819"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}