Описание
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:rocket.chat:rocket.chat:3.11.0:-:*:*:*:*:*:*
cpe:2.3:a:rocket.chat:rocket.chat:3.12.0:-:*:*:*:*:*:*
cpe:2.3:a:rocket.chat:rocket.chat:3.13.0:-:*:*:*:*:*:*
EPSS
Процентиль: 100%
0.92332
Критический
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-75
NVD-CWE-Other
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE.
EPSS
Процентиль: 100%
0.92332
Критический
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-75
NVD-CWE-Other