Stored XSS Vulnerability in Rocket.Chat Electron Desktop Application
CVE-2024-45621

5.4MEDIUM

Key Information:

Vendor
CVE Published:
2 September 2024

What is CVE-2024-45621?

The Rocket.Chat Electron desktop application version 6.3.4 is vulnerable to a stored cross-site scripting (XSS) attack. This vulnerability arises when users upload files that contain malicious links. When a file is accessed, it can trigger the execution of external actions in the user's browser, leading to potential exploitation. The issue stems from the application failing to properly handle external links from uploaded documents such as PDFs, allowing attackers to execute arbitrary scripts in the context of the user's session. This flaw highlights the importance of robust security measures and user awareness regarding file uploads and third-party actions.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-45621 : Stored XSS Vulnerability in Rocket.Chat Electron Desktop Application