Skip to content

Known CVE

Rocket.Chat <=3.13 - NoSQL Injection

Rocket.Chat 3.11, 3.12 and 3.13 contains a NoSQL injection vulnerability which allows unauthenticated access to an API endpoint. An attacker can possibly obtain sensitive information from a database, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

CVE-2021-22911

Critical2021CVSS 9.8CWE-75

cve2021 · rocketchat · nosqli · packetstorm · vulhub · hackerone · rocket.chat · sqli

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website