#VU52291 NoSQL Injection in Rocket.Chat
Published: April 16, 2021 / Updated: May 26, 2021
Rocket.Chat
Rocket.Chat Technologies Corp.
Description
The vulnerability allows a remote attacker to execute arbitrary NoSQL code in the database.
The vulnerability exists due to improper input validation. A remote non-authenticated attacker can send a specially crafted request and execute arbitrary NoSQL code in the database.
Successful exploitation of this vulnerability may result in account takeover.