NoSQL Injection Vulnerability in Rocket.Chat Server by Rocket.Chat
CVE-2017-1000493
9.8CRITICAL
What is CVE-2017-1000493?
The Rocket.Chat Server prior to version 0.59 is susceptible to a NoSQL injection vulnerability. This flaw could allow an attacker to gain unauthorized access to administrator accounts, potentially compromising the entire server's security. Exploiting this vulnerability involves sending specific crafted requests that manipulate the underlying database queries, leading to the retrieval or alteration of sensitive data. Immediate mitigation is essential to prevent unauthorized user access and maintain the integrity of the application.