Stored Cross-Site Scripting in RockMongo by iWind
CVE-2023-53938
Key Information:
Badges
What is CVE-2023-53938?
RockMongo version 1.1.7 is susceptible to a stored cross-site scripting vulnerability that permits attackers to inject malicious JavaScript through multiple unencoded input parameters. By crafting specific payloads within the database, collection, or login parameters, an attacker can execute arbitrary scripts in the browsers of unsuspecting users. This vulnerability may lead to data theft, unauthorized access, or other malicious actions that compromise the integrity and confidentiality of user data.
Affected Version(s)
RockMongo 1.1.7
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
