vendor:
RockMongo
by:
Ozer Goker
8,8
CVSS
HIGH
CSRF | HTML(or Iframe) Injection | XSS (Reflected & Stored)
352, 79, 89
CWE
Product Name: RockMongo
Affected Version From: 1.1.8
Affected Version To: 1.1.8
Patch Exists: Yes
Related CWE: N/A
CPE: a:rockmongo:rockmongo:1.1.8
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: PHP5
2016
RockMongo v1.1.8 – PHP MongoDB Administrator Multiple Vulnerabilities
RockMongo, a MongoDB administration tool, written in PHP5, is vulnerable to Cross-Site Request Forgery (CSRF), HTML Injection and Cross-Site Scripting (XSS) vulnerabilities. The XSS vulnerabilities include reflected and stored XSS. The reflected XSS can be exploited by sending a maliciously crafted URL to the victim, while the stored XSS can be exploited by sending a maliciously crafted POST request to the vulnerable application.
Mitigation:
The vendor has released a patch to address the vulnerabilities. Users are advised to upgrade to the latest version of RockMongo.