← Back

CVE-2024-46934

nvd nist
Published: Sep 25, 2024Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to DOM-based Cross-site Scripting (XSS). Attackers may be able to abuse the UpdateOTRAck method to forge a message that contains an XSS payload.

Affected (12)

1 product
Rocket.chat
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Rocket.chat
Before 6.7.9
From 6.10.0 to 6.10.6
From 6.11.0 to 6.11.3
From 6.8.0 to 6.8.7
From 6.9.0 to 6.9.7
Version 6.12.0
Version 6.12.0 rc1
Version 6.12.0 rc2
Version 6.12.0 rc3
Version 6.12.0 rc4
Version 6.12.0 rc5
Version 6.12.0 rc6

Timeline

No history available yet.