CVE-2023-53938
MEDIUMRockMongo 1.1.7 - XSS
Title source: llmDescription
RockMongo 1.1.7 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts through multiple unencoded input parameters. Attackers can exploit the vulnerability by submitting crafted payloads in database, collection, and login parameters to execute arbitrary JavaScript in victim's browser.
Exploits (1)
Scores
CVSS v3
5.4
EPSS
0.0005
EPSS Percentile
16.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
iwind/RockMongo
1.1.7
rockmongo/rockmongo
1.1.7
Published
Dec 18, 2025
Tracked Since
Feb 18, 2026