Show filters
102 Total Results
Displaying 41-50 of 102
Sort by:
Attacker Value
Unknown
CVE-2022-25026
Disclosure Date: January 12, 2023 (last updated October 08, 2023)
A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on the internal network via a crafted HTTP request to /trufusionPortal/upDwModuleProxy.
0
Attacker Value
Unknown
CVE-2022-44567
Disclosure Date: December 23, 2022 (last updated October 08, 2023)
A command injection vulnerability exists in Rocket.Chat-Desktop <3.8.14 that could allow an attacker to pass a malicious url of openInternalVideoChatWindow to shell.openExternal(), which may lead to remote code execution (internalVideoChatWindow.ts#L17). To exploit the vulnerability, the internal video chat window must be disabled or a Mac App Store build must be used (internalVideoChatWindow.ts#L14). The vulnerability may be exploited by an XSS attack because the function openInternalVideoChatWindow is exposed in the Rocket.Chat-Desktop-API.
0
Attacker Value
Unknown
CVE-2022-38488
Disclosure Date: December 14, 2022 (last updated October 08, 2023)
logrocket-oauth2-example through 2020-05-27 allows SQL injection via the /auth/register username parameter.
0
Attacker Value
Unknown
CVE-2022-36431
Disclosure Date: December 01, 2022 (last updated October 08, 2023)
An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a crafted JSP file. Issue fixed in version 7.9.6.1.
0
Attacker Value
Unknown
CVE-2022-3136
Disclosure Date: October 10, 2022 (last updated October 08, 2023)
The Social Rocket WordPress plugin before 1.3.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2022-35251
Disclosure Date: September 23, 2022 (last updated October 08, 2023)
A cross-site scripting vulnerability exists in Rocket.chat <v5 due to style injection in the complete chat window, an adversary is able to manipulate not only the style of it, but will also be able to block functionality as well as hijacking the content of targeted users. Hence the payloads are stored in messages, it is a persistent attack vector, which will trigger as soon as the message gets viewed.
0
Attacker Value
Unknown
CVE-2022-35250
Disclosure Date: September 23, 2022 (last updated October 08, 2023)
A privilege escalation vulnerability exists in Rocket.chat <v5 which made it possible to elevate privileges for any authenticated user to view Direct messages without appropriate permissions.
0
Attacker Value
Unknown
CVE-2022-35249
Disclosure Date: September 23, 2022 (last updated October 08, 2023)
A information disclosure vulnerability exists in Rocket.Chat <v5 where the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.
0
Attacker Value
Unknown
CVE-2022-35248
Disclosure Date: September 23, 2022 (last updated October 08, 2023)
A improper authentication vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 that allowed two factor authentication can be bypassed when telling the server to use CAS during login.
0
Attacker Value
Unknown
CVE-2022-35247
Disclosure Date: September 23, 2022 (last updated October 08, 2023)
A information disclosure vulnerability exists in Rocket.chat <v5, <v4.8.2 and <v4.7.5 where the lack of ACL checks in the getRoomRoles Meteor method leak channel members with special roles to unauthorized clients.
0