Skip to main content

CVE-2021-22911

Description

A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE.

NVD
Severity: CRITICAL
CVE ID: CVE-2021-22911
CVSS Score: 9.8
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Refrence: NVDMITRE

Proof Of Concept

Nuclei Templates for CVE-2021-22911
CsEnox

Pre-Auth Blind NoSQL Injection leading to Remote Code Execution in Rocket Chat 3.12.1

Refrence: GitHub

optionalCTF

Full unauthenticated RCE proof of concept for Rocket.Chat 3.12.1 CVE-2021-22911

Refrence: GitHub

jayngng

Modifed ver of the original exploit to save some times on password reseting for unprivileged user

Refrence: GitHub

ChrisPritchard

exploit for CVE-2021-22911 in rust

Refrence: GitHub

MrDottt

Refrence: GitHub

overgrowncarrot1

Refrence: GitHub