Show filters
102 Total Results
Displaying 71-80 of 102
Sort by:
Attacker Value
Unknown
CVE-2021-22910
Disclosure Date: August 09, 2021 (last updated February 23, 2025)
A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could result in a NoSQL injection, potentially leading to RCE.
0
Attacker Value
Unknown
CVE-2020-26763
Disclosure Date: July 05, 2021 (last updated November 28, 2024)
The Rocket.Chat desktop application 2.17.11 opens external links without user interaction.
0
Attacker Value
Unknown
CVE-2021-22911
Disclosure Date: May 27, 2021 (last updated February 22, 2025)
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE.
0
Attacker Value
Unknown
CVE-2021-22892
Disclosure Date: May 27, 2021 (last updated February 22, 2025)
An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be disclosed by enumeration and validation checks.
0
Attacker Value
Unknown
CVE-2021-29935
Disclosure Date: April 01, 2021 (last updated February 22, 2025)
An issue was discovered in the rocket crate before 0.4.7 for Rust. uri::Formatter can have a use-after-free if a user-provided function panics.
0
Attacker Value
Unknown
CVE-2021-22886
Disclosure Date: March 26, 2021 (last updated February 22, 2025)
Rocket.Chat before 3.11, 3.10.5, 3.9.7, 3.8.8 is vulnerable to persistent cross-site scripting (XSS) using nested markdown tags allowing a remote attacker to inject arbitrary JavaScript in a message. This flaw leads to arbitrary file read and RCE on Rocket.Chat desktop app.
0
Attacker Value
Unknown
CVE-2020-8292
Disclosure Date: January 26, 2021 (last updated February 22, 2025)
Rocket.Chat server before 3.9.0 is vulnerable to a self cross-site scripting (XSS) vulnerability via the drag & drop functionality in message boxes.
0
Attacker Value
Unknown
CVE-2020-8288
Disclosure Date: January 26, 2021 (last updated February 22, 2025)
The `specializedRendering` function in Rocket.Chat server before 3.9.2 allows a cross-site scripting (XSS) vulnerability by way of the `value` parameter.
0
Attacker Value
Unknown
CVE-2020-27852
Disclosure Date: January 20, 2021 (last updated February 22, 2025)
A stored Cross-Site Scripting (XSS) vulnerability in the survey feature in Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary web script or HTML via a textarea field. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).
0
Attacker Value
Unknown
CVE-2020-27851
Disclosure Date: January 20, 2021 (last updated February 22, 2025)
Multiple stored HTML injection vulnerabilities in the "poll" and "quiz" features in an additional paid add-on of Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary HTML code via poll or quiz answers. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).
0