CVE-2023-28359: SQL Injection
A NoSQL injection vulnerability has been identified in the listEmojiCustom method call within Rocket.Chat. This can be exploited by unauthenticated users when there is at least one custom emoji uploaded to the Rocket.Chat instance. The vulnerability causes a delay in the server response, with the potential for limited impact.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28359?
CVE-2023-28359 has been classified as a high-severity vulnerability due to its potential impact on server response times.
How do I fix CVE-2023-28359?
To remediate CVE-2023-28359, ensure that your Rocket.Chat instance is updated to version 6.0.0 or later.
Who is affected by CVE-2023-28359?
CVE-2023-28359 affects all versions of Rocket.Chat prior to 6.0.0 that have custom emojis uploaded.
Can CVE-2023-28359 be exploited by authenticated users?
No, CVE-2023-28359 can be exploited by unauthenticated users.
What impact does CVE-2023-28359 have on server performance?
CVE-2023-28359 may cause a delay in server response when the vulnerability is exploited.