First published: Mon Sep 02 2024(Updated: )
The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related to failure to use a separate browser upon encountering third-party external actions from PDF documents.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rocket.Chat Rocket.Chat | <=6.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.