Message Deletion Bypass in Rocket.Chat by Rocket.Chat
CVE-2023-28318
5.3MEDIUM
What is CVE-2023-28318?
A vulnerability in Rocket.Chat allows users to conceal messages irrespective of the server configurations for Message_KeepHistory or Message_ShowDeletedStatus. This flaw enables a circumvention of the original message deletion protocol, thus preventing messages and their deletion notifications from being properly displayed. As a result, this could lead to potential data leaks and undermine the integrity of message management within the platform.
Affected Version(s)
Rocket.Chat This issue has been fixed in version 6.0> and is backported for the supported versions. Check this document for more info: https://docs.rocket.chat/resources/get-support/enterprise-support#rocket.chat-versions