AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-24760

CRITICAL · CVSS 10 EPSS 49.08% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-03-12 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2022-24760
Severity
CRITICAL
CVSS
10
EPSS
49.08%
Windows MongoDB Linux Ubuntu

Original NVD Description

Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Server. This vulnerability affects Parse Server in the default configuration with MongoDB. The main weakness that leads to RCE is the Prototype Pollution vulnerable code in the file `DatabaseController.js`, so it is likely to affect Postgres and any other database backend as well. This vulnerability has been confirmed on Linux (Ubuntu) and Windows. Users are advised to upgrade as soon as possible. The only known workaround is to manually patch your installation with code referenced at the source GHSA-p6h4-93qp-jhcm.

Related CVEs

Other vulnerabilities affecting the same vendor(s)