Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gj39-fcfm-v6w8

Опубликовано: 12 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the updateMessage method that only checks whether the user is allowed to edit message in the target room.

An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the updateMessage method that only checks whether the user is allowed to edit message in the target room.

EPSS

Процентиль: 41%
0.0019
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-285
CWE-287
CWE-863

Связанные уязвимости

CVSS3: 6.5
nvd
больше 2 лет назад

An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the updateMessage method that only checks whether the user is allowed to edit message in the target room.

EPSS

Процентиль: 41%
0.0019
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-285
CWE-287
CWE-863