Files
CVEs-PoC/2021/CVE-2021-22911.md
T
2024-06-18 02:51:15 +02:00

42 lines
2.0 KiB
Markdown

### [CVE-2021-22911](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22911)
![](https://img.shields.io/static/v1?label=Product&message=Rocket.Chat%20server&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Failure%20to%20Sanitize%20Special%20Elements%20into%20a%20Different%20Plane%20(Special%20Element%20Injection)%20(CWE-75)&color=brighgreen)
### Description
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE.
### POC
#### Reference
- http://packetstormsecurity.com/files/162997/Rocket.Chat-3.12.1-NoSQL-Injection-Code-Execution.html
- http://packetstormsecurity.com/files/163419/Rocket.Chat-3.12.1-NoSQL-Injection-Code-Execution.html
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/ARPSyndicate/kenzer-templates
- https://github.com/ChrisPritchard/CVE-2021-22911-rust
- https://github.com/CsEnox/CVE-2021-22911
- https://github.com/MrDottt/CVE-2021-22911
- https://github.com/NaInSec/CVE-PoC-in-GitHub
- https://github.com/SYRTI/POC_to_review
- https://github.com/SleepwalkrX/Authenticated-RocketChat-3.12.1-Reverse-Shell
- https://github.com/Threekiii/Awesome-POC
- https://github.com/Threekiii/Vulhub-Reproduce
- https://github.com/WhooAmii/POC_to_review
- https://github.com/bakery312/Vulhub-Reproduce
- https://github.com/jayngng/CVE-2021-22911
- https://github.com/k0mi-tg/CVE-POC
- https://github.com/manas3c/CVE-POC
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/optionalCTF/Rocket.Chat-Automated-Account-Takeover-RCE-CVE-2021-22911
- https://github.com/overgrowncarrot1/CVE-2021-22911
- https://github.com/soosmile/POC
- https://github.com/trhacknon/Pocingit
- https://github.com/vlrhsgody/CVE-2021-22911
- https://github.com/whoforget/CVE-POC
- https://github.com/youwizard/CVE-POC
- https://github.com/zecool/cve