PT-2022-15163 · Rocket.Chat · Rocketchat Livechat

Cyberasset

·

Published

2022-04-01

·

Updated

2022-04-08

·

CVE-2022-21830

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions RocketChat LiveChat versions prior to 1.9
Description A blind self XSS issue exists that could allow an attacker to trick a victim into pasting malicious code in their chat instance. This could potentially lead to the execution of unauthorized code within the victim's chat instance.
Recommendations For versions prior to 1.9, update to version 1.9 or later to resolve the issue. As a temporary workaround, consider restricting the ability for users to paste code in their chat instances until a patch is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-21830
GHSA-HF55-C445-2W97

Affected Products

Rocketchat Livechat