PT-2022-22659 · Unknown · Rocket.Chat

Danieljpp

·

Published

2022-09-23

·

Updated

2022-09-26

·

CVE-2022-35251

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Rocket.chat versions prior to 5
Description A cross-site scripting issue exists due to style injection in the complete chat window. This allows an adversary to manipulate the style, block functionality, and hijack the content of targeted users. The payloads are stored in messages, making it a persistent attack vector that triggers when the message is viewed.
Recommendations For versions prior to 5, update to version 5 or later to resolve the issue. As a temporary workaround, consider restricting the use of styled messages in the chat window until a patch is available. Avoid viewing suspicious messages that may contain malicious payloads.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-35251

Affected Products

Rocket.Chat