CyberRota Analysis
AI-GeneratedThe MongoSQL Transition Readiness Tool is vulnerable due to improper encoding of query text and usernames from BI Connector log files in its generated HTML reports. This flaw allows an attacker with query access to manipulate log content, potentially disclosing sensitive information or misleading operators when reports are viewed in a browser. Organizations using the BI Connector should prioritize addressing this vulnerability to mitigate risks of information leakage and ensure data integrity.
Original NVD Description
The MongoSQL Transition Readiness Tool writes query text and user names read from BI Connector log files into its generated HTML report without encoding them for that output context. A user able to issue queries through the BI Connector can influence log content so that markup supplied in a query is interpreted by the browser when an operator later generates and opens the report, which may disclose other users' logged query text and user names to an external party or present misleading content to the operator. Generating a report over logs containing the affected entries and opening that report in a browser is required.
Related CVEs
Other vulnerabilities affecting the same vendor(s)