Cross-Site Scripting Vulnerability in Rocket.Chat Server
CVE-2020-8288
5.4MEDIUM
What is CVE-2020-8288?
The specializedRendering
function in Rocket.Chat Server versions before 3.9.2 is prone to a Cross-Site Scripting (XSS) vulnerability. This issue is triggered by a crafted value
parameter, allowing attackers to inject malicious scripts into web pages viewed by other users. If exploited, this vulnerability could enable unauthorized access to user data or manipulation of web content.
Affected Version(s)
Rocket.Chat server Fixed in 3.9.2