Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wc38-cjg3-q72x

Опубликовано: 12 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

A vulnerability has been discovered in Rocket.Chat where a markdown parsing issue in the "Search Messages" feature allows the insertion of malicious tags. This can be exploited on servers with content security policy disabled possible leading to some issues attacks like account takeover.

A vulnerability has been discovered in Rocket.Chat where a markdown parsing issue in the "Search Messages" feature allows the insertion of malicious tags. This can be exploited on servers with content security policy disabled possible leading to some issues attacks like account takeover.

EPSS

Процентиль: 60%
0.00393
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 2 лет назад

A vulnerability has been discovered in Rocket.Chat where a markdown parsing issue in the "Search Messages" feature allows the insertion of malicious tags. This can be exploited on servers with content security policy disabled possible leading to some issues attacks like account takeover.

EPSS

Процентиль: 60%
0.00393
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79