NoSQL Injection @ sequelize

  • module : sequelize
  • version : <4.12.0
  • severity: high
  • type: nosql-injection

Installation

docker-compose up --build

Lunch Attack

OR

OR

  • Bash [open the terminal in the root dir of this app and run the following]

    bash attack.sh
  • the response will be {"id":1,"uid":1,"name":"Doe","createdAt":"...","updatedAt":"..."}