If it not exists let you login and get access to any account(with the password parameter) using the password the attacker put in the get req to see this: cancel this line,open postman on login req and enter in the body: { "email":{"$gt":""}, "password": "pass1234" }
-
Notifications
You must be signed in to change notification settings - Fork 0
EladAvrahami/express-mongoDB
Folders and files
Name | Name | Last commit message | Last commit date | |
---|---|---|---|---|
Repository files navigation
About
No description, website, or topics provided.
Resources
Stars
Watchers
Forks
Releases
No releases published
Packages 0
No packages published