CVE-2021-22911
Description
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE.
NVD
Severity: CRITICAL
CVE ID: CVE-2021-22911
CVSS Score: 9.8
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Proof Of Concept
Nuclei Templates for CVE-2021-22911
Refrence: Project Discovery GitHub
CsEnox
Pre-Auth Blind NoSQL Injection leading to Remote Code Execution in Rocket Chat 3.12.1
Refrence: GitHub
optionalCTF
Full unauthenticated RCE proof of concept for Rocket.Chat 3.12.1 CVE-2021-22911
Refrence: GitHub
jayngng
Modifed ver of the original exploit to save some times on password reseting for unprivileged user
Refrence: GitHub
ChrisPritchard
exploit for CVE-2021-22911 in rust
Refrence: GitHub
MrDottt
Refrence: GitHub
overgrowncarrot1
Refrence: GitHub