CVE-2021-22911
CRITICAL EXPLOITED NUCLEIRocket.Chat <3.14 - SQL Injection
Title source: llmDescription
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE.
Exploits (16)
exploitdb
WORKING POC
VERIFIED
by enox · pythonwebappslinux
https://www.exploit-db.com/exploits/50108
exploitdb
WORKING POC
VERIFIED
by enox · pythonwebappslinux
https://www.exploit-db.com/exploits/49960
github
34 stars
by DarkFunct · cpoc
https://github.com/DarkFunct/CVE_Exploits/tree/main/CVE-2021-22911
nomisec
WORKING POC
9 stars
by optionalCTF · poc
https://github.com/optionalCTF/Rocket.Chat-Automated-Account-Takeover-RCE-CVE-2021-22911
nomisec
WORKING POC
by roshanrajbanshi · poc
https://github.com/roshanrajbanshi/rocketcat-cve-2021-22911-exploit
nomisec
WORKING POC
by Faridi-m · remote-auth
https://github.com/Faridi-m/CVE-2021-22911-RocketChat-Improvised-
nomisec
WORKING POC
by TeneBrae93 · remote
https://github.com/TeneBrae93/RocketChat-NoSQLi-Chain-CVE-2021-22911
nomisec
WORKING POC
by yoohhuu · remote-auth
https://github.com/yoohhuu/Rocket-Chat-3.12.1-PoC-CVE-2021-22911-
nomisec
WORKING POC
by ChrisPritchard · remote
https://github.com/ChrisPritchard/CVE-2021-22911-rust
Nuclei Templates (1)
Rocket.Chat <=3.13 - NoSQL Injection
CRITICALVERIFIEDby tess,sullo
Shodan:
http.title:"Rocket.Chat" || http.title:"rocket.chat"
FOFA:
title="rocket.chat"
References (4)
Scores
CVSS v3
9.8
EPSS
0.9233
EPSS Percentile
99.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2023-11-14
CWE
CWE-75
Status
published
Products (3)
rocket.chat/rocket.chat
3.11.0
rocket.chat/rocket.chat
3.12.0
rocket.chat/rocket.chat
3.13.0
Published
May 27, 2021
Tracked Since
Feb 18, 2026