A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE.
PoC: CVE-2021-22911
Pre-Auth Blind NoSQL Injection leading to Remote Code Execution in Rocket Chat 3.12.1
PoC: Rocket.Chat-Automated-Account-Takeover-RCE-CVE-2021-22911
Full unauthenticated RCE proof of concept for Rocket.Chat 3.12.1 CVE-2021-22911
PoC: rocketcat-cve-2021-22911-exploit
CVE-2021-22911 Rocket.Chat NoSQL Injection RCE Exploit - Educational Purpose
PoC: CVE-2021-22911
Updated exploit for CVE-2021-22911 (Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated))
PoC: CVE-2021-22911-EXP
some small changes to the code by CsEnox
PoC: CVE-2021-22911-rust
exploit for CVE-2021-22911 in rust
PoC: CVE-2021-22911
Modifed ver of the original exploit to save some times on password reseting for unprivileged user
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free