Product
A vulnerability in Parse Server's device token deduplication logic allows unauthenticated remote attackers to inject NoSQL query operators, leading to unauthorized deletion of device registrations.