First published: Fri Apr 01 2022(Updated: )
A blind self XSS vulnerability exists in RocketChat LiveChat <v1.9 that could allow an attacker to trick a victim pasting malicious code in their chat instance.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rocket.chat Livechat | <1.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this blind self XSS vulnerability is CVE-2022-21830.
The affected software for CVE-2022-21830 is RocketChat LiveChat version 1.9.0 and below.
The severity keyword for CVE-2022-21830 is medium.
The severity value for CVE-2022-21830 is 6.1.
Yes, there is a reference available for CVE-2022-21830. You can find it at https://hackerone.com/reports/1091118.