PT-2022-22659 · Unknown · Rocket.Chat
Danieljpp
·
Published
2022-09-23
·
Updated
2022-09-26
·
CVE-2022-35251
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Rocket.chat versions prior to 5
Description
A cross-site scripting issue exists due to style injection in the complete chat window. This allows an adversary to manipulate the style, block functionality, and hijack the content of targeted users. The payloads are stored in messages, making it a persistent attack vector that triggers when the message is viewed.
Recommendations
For versions prior to 5, update to version 5 or later to resolve the issue. As a temporary workaround, consider restricting the use of styled messages in the chat window until a patch is available. Avoid viewing suspicious messages that may contain malicious payloads.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rocket.Chat