CVE-2024-45621
Last modified
CVE-2024-45621 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related to failure to use a separate browser upon encountering third-party external actions from PDF documents.. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related to failure to use a separate browser upon encountering third-party external actions from PDF documents.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rocket.Chat | Rocket.Chat | <= 6.3.4 |
References
- https://hackerone.com/reports/1967109Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-45621?
How severe is CVE-2024-45621?
How do I fix CVE-2024-45621?
Are you affected by CVE-2024-45621?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
