CVE-2021-22911
84Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 95%
from disclosure to weapon9 days
Published on NVDMay 27
1st PoC+9d
VulnCheck+901d
exploitation probability
95%top 1% of all CVEs
observed exploitation
yesVulnCheck
26 public exploit(s)
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE.
Affected products
n/a · Rocket.Chat serverpublic PoCs found — 26✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/49960exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/50108githubgithub.com/CsEnox/CVE-2021-22911★ 61githubgithub.com/optionalCTF/Rocket.Chat-Automated-Account-Takeover-RCE-CVE-2021-22911★ 9githubgithub.com/Faridi-m/CVE-2021-22911-RocketChat★ 2githubgithub.com/octodi/CVE-2021-22911★ 0githubgithub.com/TeneBrae93/RocketChat-NoSQLi-Chain-CVE-2021-22911★ 0githubgithub.com/roshanrajbanshi/rocketcat-cve-2021-22911-exploit★ 0githubgithub.com/MrDottt/CVE-2021-22911★ 0githubgithub.com/jayngng/CVE-2021-22911★ 0githubgithub.com/ChrisPritchard/CVE-2021-22911-rust★ 0githubgithub.com/overgrowncarrot1/CVE-2021-22911★ 0githubgithub.com/yoohhuu/Rocket-Chat-3.12.1-PoC-CVE-2021-22911-★ 0vulncheckvulncheck.com/xdb/7e30455fc824unverifiedcve_referencepacketstormsecurity.com/files/163419/Rocket.Chat-3.12.1-NoSQL-Injection-Code-Execution.htmlunverifiedvulncheckvulncheck.com/xdb/fea071c9ad62unverifiedvulncheckvulncheck.com/xdb/d1c0203f5bc0unverifiedvulncheckvulncheck.com/xdb/94fbab710c8eunverifiedvulncheckvulncheck.com/xdb/9bf9c3e084beunverifiedvulncheckvulncheck.com/xdb/6d83697d150eunverifiedvulncheckvulncheck.com/xdb/0beee03e8b56unverifiedvulncheckvulncheck.com/xdb/eedeb345f12bunverifiedvulncheckvulncheck.com/xdb/5eec00088786unverifiedvulncheckvulncheck.com/xdb/4c114b9573beunverifiedvulncheckvulncheck.com/xdb/94a3e2ed78d5unverifiedcve_referencepacketstormsecurity.com/files/162997/Rocket.Chat-3.12.1-NoSQL-Injection-Code-Execution.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/162997/Rocket.Chat-3.12.1-NoSQL-Injection-Code-Execution.htmlhttp://packetstormsecurity.com/files/163419/Rocket.Chat-3.12.1-NoSQL-Injection-Code-Execution.htmlhttps://blog.sonarsource.com/nosql-injections-in-rocket-chathttps://hackerone.com/reports/1130721