Improper access control in parse-server - CVE-2020-5251
Published: March 3, 2020 / Updated: May 23, 2026
parse-server
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the users endpoint when processing NoSQL queries containing regex operators on sessionToken values. A remote attacker can send a specially crafted request to disclose sensitive information.
The issue can be exploited without user interaction by using regex matching to identify valid accounts.