RockMongo 1.1.7 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts through multiple unencoded input parameters. Attackers can exploit the vulnerability by submitting crafted payloads in database, collection, and login parameters to execute arbitrary JavaScript in victim's browser.
History

Fri, 19 Dec 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Rockmongo
Rockmongo rockmongo
Vendors & Products Rockmongo
Rockmongo rockmongo

Thu, 18 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 20:00:00 +0000

Type Values Removed Values Added
Description RockMongo 1.1.7 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts through multiple unencoded input parameters. Attackers can exploit the vulnerability by submitting crafted payloads in database, collection, and login parameters to execute arbitrary JavaScript in victim's browser.
Title RockMongo 1.1.7 Stored Cross-Site Scripting Vulnerability via Multiple Parameters
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-18T19:53:34.159Z

Updated: 2025-12-18T21:47:05.162Z

Reserved: 2025-12-16T19:22:09.997Z

Link: CVE-2023-53938

cve-icon Vulnrichment

Updated: 2025-12-18T21:03:43.812Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-18T20:15:52.160

Modified: 2025-12-19T18:00:18.330

Link: CVE-2023-53938

cve-icon Redhat

No data.