NoSQLi
Last updated
Was this helpful?
Last updated
Was this helpful?
The example below is based on PostSwigger's lab.
A simplified example of how mongodb
queries filters data using can be found below (Figure 1).
Replicating the above authentication bypass attempt does not seem to work (Figure 2).
The error message indicates that we might not have an exact match for the administrator
username. Thus, we can try injecting a regex payload for the username
parameter (Figure 3 & 4).
To solve the lab, the cookie must be entered manually through the browser.
username
parameter.