First published: Tue Sep 24 2024(Updated: )
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to DOM-based Cross-site Scripting (XSS). Attackers may be able to abuse the UpdateOTRAck method to forge a message that contains an XSS payload.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rocket.Chat Rocket.Chat | <6.7.9 | |
Rocket.Chat Rocket.Chat | >=6.8.0<6.8.7 | |
Rocket.Chat Rocket.Chat | >=6.9.0<6.9.7 | |
Rocket.Chat Rocket.Chat | >=6.10.0<6.10.6 | |
Rocket.Chat Rocket.Chat | >=6.11.0<6.11.3 | |
Rocket.Chat Rocket.Chat | =6.12.0 | |
Rocket.Chat Rocket.Chat | =6.12.0-rc1 | |
Rocket.Chat Rocket.Chat | =6.12.0-rc2 | |
Rocket.Chat Rocket.Chat | =6.12.0-rc3 | |
Rocket.Chat Rocket.Chat | =6.12.0-rc4 | |
Rocket.Chat Rocket.Chat | =6.12.0-rc5 | |
Rocket.Chat Rocket.Chat | =6.12.0-rc6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.