Rocket.Chat version 0.8.0 and newer is vulnerable to XSS in the markdown link parsing code for messages.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://www.theblazehen.com/posts/CVE-2017-xxxxxx-rocketchat-xss-with-markdown-url-handling-in-messages/ | broken link url repurposed |