Back to directory
WRITEUP #3735

NoSQL Injections in Rocket.Chat 3.12.1: How A Small Leak Grounds A Rocket

SQL InjectionNoSQL injectionRCE
byPaul Gerste
Program
Rocket.Chat
Published
May 18, 2021
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://www.sonarsource.com/blog/nosql-injections-in-rocket-chat/
RELATED WRITEUPS
Exploiting authorization by nonce in WordPress plugins
RCEArbitrary file upload
Vulnerabilities in Open Source C2 Frameworks
RCEOS command injection
[2,500$ Bug Bounty Write-Up] Remote Code Execution (RCE) via unclaimed Node package
RCEDependency confusion
Attacking PowerShell CLIXML Deserialization
DeserializationInsecure deserialization
Zero-Click Calendar invite — Critical zero-click vulnerability chain in macOS
RCEArbitrary file write

Built with ❤️ by Shubham Rawat