Stored XSS Vulnerability in Rocket.Chat Electron Desktop Application
CVE-2024-45621
5.4MEDIUM
What is CVE-2024-45621?
The Rocket.Chat Electron desktop application version 6.3.4 is vulnerable to a stored cross-site scripting (XSS) attack. This vulnerability arises when users upload files that contain malicious links. When a file is accessed, it can trigger the execution of external actions in the user's browser, leading to potential exploitation. The issue stems from the application failing to properly handle external links from uploaded documents such as PDFs, allowing attackers to execute arbitrary scripts in the context of the user's session. This flaw highlights the importance of robust security measures and user awareness regarding file uploads and third-party actions.