CVE Database
/

CVE-2021-22886

Back to search

CVE-2021-22886

Published: Mar 26, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

Rocket.Chat before 3.11, 3.10.5, 3.9.7, 3.8.8 is vulnerable to persistent cross-site scripting (XSS) using nested markdown tags allowing a remote attacker to inject arbitrary JavaScript in a message. This flaw leads to arbitrary file read and RCE on Rocket.Chat desktop app.

VendorProductVersions

n/a

Rocket.Chat

affected
Fixed in 3.11, 3.10.5, 3.9.7, 3.8.8

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now