CVE-2024-45621: XSS
The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related to failure to use a separate browser upon encountering third-party external actions from PDF documents.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45621?
CVE-2024-45621 is classified as a medium severity vulnerability due to its potential for exploitation via stored cross-site scripting (XSS).
How do I fix CVE-2024-45621?
To fix CVE-2024-45621, upgrade Rocket.Chat to version 6.3.5 or later where this vulnerability is addressed.
What kind of attack can be executed with CVE-2024-45621?
CVE-2024-45621 allows attackers to perform stored XSS attacks through malicious links in uploaded files.
What versions of Rocket.Chat are affected by CVE-2024-45621?
CVE-2024-45621 affects Rocket.Chat versions up to and including 6.3.4.
Is there a workaround for CVE-2024-45621?
Currently, the best approach to mitigate CVE-2024-45621 is to upgrade to the patched version of Rocket.Chat.