CVE-2024-46934
- EPSS 0.11%
- Veröffentlicht 25.09.2024 01:15:44
- Zuletzt bearbeitet 25.03.2025 17:16:10
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to DOM-based Cross-site Scripting (XSS). Attackers may be able to abuse the UpdateOTRAck method to forge a message that contains an XSS payload.
CVE-2024-45621
- EPSS 0.16%
- Veröffentlicht 02.09.2024 19:15:13
- Zuletzt bearbeitet 13.03.2025 21:15:41
The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related to failure to use a separate browser upon encountering third-party external actions from PDF documents.
CVE-2024-39713
- EPSS 89.53%
- Veröffentlicht 05.08.2024 05:15:39
- Zuletzt bearbeitet 06.09.2024 17:35:12
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
CVE-2024-37405
- EPSS 0.33%
- Veröffentlicht 12.07.2024 16:15:03
- Zuletzt bearbeitet 15.04.2026 00:35:42
Livechat messages can be leaked by combining two NoSQL injections affecting livechat:loginByToken (pre-authentication) and livechat:loadHistory.
CVE-2023-28359
- EPSS 0.17%
- Veröffentlicht 11.05.2023 22:15:10
- Zuletzt bearbeitet 27.01.2025 17:15:11
A NoSQL injection vulnerability has been identified in the listEmojiCustom method call within Rocket.Chat. This can be exploited by unauthenticated users when there is at least one custom emoji uploaded to the Rocket.Chat instance. The vulnerability ...
CVE-2023-28358
- EPSS 0.39%
- Veröffentlicht 11.05.2023 22:15:09
- Zuletzt bearbeitet 27.01.2025 17:15:11
A vulnerability has been discovered in Rocket.Chat where a markdown parsing issue in the "Search Messages" feature allows the insertion of malicious tags. This can be exploited on servers with content security policy disabled possible leading to some...
CVE-2023-28357
- EPSS 0.12%
- Veröffentlicht 11.05.2023 22:15:09
- Zuletzt bearbeitet 27.01.2025 18:15:33
A vulnerability has been identified in Rocket.Chat, where the ACL checks in the Slash Command /mute occur after checking whether a user is a member of a given channel, leaking private channel members to unauthorized users. This allows authenticated u...
CVE-2023-28356
- EPSS 0.27%
- Veröffentlicht 11.05.2023 22:15:09
- Zuletzt bearbeitet 27.01.2025 17:15:11
A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to enter a hot loop on one of the processes, consuming ~120% CPU and rendering the service unresponsive.
CVE-2023-28325
- EPSS 0.19%
- Veröffentlicht 11.05.2023 22:15:09
- Zuletzt bearbeitet 27.01.2025 17:15:11
An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the updateMessage method that only checks whether the user is allowed to edit message in the target room.
CVE-2023-28318
- EPSS 0.04%
- Veröffentlicht 09.05.2023 22:15:10
- Zuletzt bearbeitet 28.01.2025 21:15:14
A vulnerability has been discovered in Rocket.Chat, where messages can be hidden regardless of the Message_KeepHistory or Message_ShowDeletedStatus server configuration. This allows users to bypass the intended message deletion behavior, hiding messa...