Known CVE
Rocket.Chat <=3.13 - NoSQL Injection
Rocket.Chat 3.11, 3.12 and 3.13 contains a NoSQL injection vulnerability which allows unauthenticated access to an API endpoint. An attacker can possibly obtain sensitive information from a database, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
CVE-2021-22911
Critical2021CVSS 9.8CWE-75
cve2021 · rocketchat · nosqli · packetstorm · vulhub · hackerone · rocket.chat · sqli
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website