S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-22911 Scanner

CVE-2021-22911 scanner - SQL Injection vulnerability in Rocket.Chat server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
2
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-22911
9.8
CVSS

A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Rocket.Chat serverby n/a
Fixed in: 3.13.2, 3.12.4, 3.11.4
Updated Aug 21, 2026View on NVD →
Detail

Rocket.Chat server is a popular communication platform used by organizations and individuals alike. This open-source server allows users to create their own private chat rooms or join public ones, share files, and collaborate on projects in real-time. It is known for its flexibility and customizability, making it a preferred choice for many businesses looking for an intuitive communication tool.

However, recently, a vulnerability in Rocket.Chat server dubbed as CVE-2021-22911 has been detected. This vulnerability is caused by an improper input sanitization issue present in versions 3.11, 3.12 and 3.13. If exploited, the flaw could lead to unauthenticated NoSQL injection, potentially resulting in remote code execution (RCE). This could be exploited by attackers to gain unauthorized access to sensitive data, allowing them to execute malicious code on the affected server.

The impact of this vulnerability can be severe as attackers can use it as an entry point to launch further attacks, such as planting malicious files or stealing sensitive information. An attacker may use this vulnerability to steal user credentials, execute arbitrary code or even take control of the targeted server, which would be disastrous for businesses and organizations.

s4e.io is an excellent platform that provides in-depth information on vulnerabilities present in digital assets, including Rocket.Chat server. It offers an easy and quick way to detect, manage, and remediate vulnerabilities in real-time with the pro features. By leveraging the site's services, businesses and organizations can easily and quickly learn about vulnerabilities present in their digital assets and address them before they are exploited.

 

REFERENCES

Solution Advice

To protect against this vulnerability, several measures can be taken. These include:

  • Keeping Rocket.Chat server up to date with the latest security patches.
  • Enabling two-factor authentication (2FA) to provide additional security.
  • Limiting access to the Rocket.Chat server to only authorized personnel.
  • Installing a web application firewall (WAF) to filter out malicious traffic.
  • Implementing a robust backup and recovery plan to ensure data can be restored in the event of an attack.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-22911 scanner - SQL Injection vulnerability in Rocket.Chat server | S4E