First published: Tue Aug 18 2020(Updated: )
Rocket.Chat through 3.4.2 allows XSS where an attacker can send a specially crafted message to a channel or in a direct message to the client which results in remote code execution on the client side.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rocket.Chat Rocket.Chat | <=3.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.