CVE-2023-53938

MEDIUM

RockMongo 1.1.7 - XSS

Title source: llm

Description

RockMongo 1.1.7 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts through multiple unencoded input parameters. Attackers can exploit the vulnerability by submitting crafted payloads in database, collection, and login parameters to execute arbitrary JavaScript in victim's browser.

Exploits (1)

exploitdb WORKING POC
by Rafael Pedrero · textwebappsphp
https://www.exploit-db.com/exploits/51437

Scores

CVSS v3 5.4
EPSS 0.0005
EPSS Percentile 16.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
iwind/RockMongo 1.1.7
rockmongo/rockmongo 1.1.7
Published Dec 18, 2025
Tracked Since Feb 18, 2026