CVE-2024-45621
02.09.2024, 19:15
The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related to failure to use a separate browser upon encountering third-party external actions from PDF documents.
Vendor | Product | Version |
---|---|---|
rocket.chat | rocket.chat | 𝑥 ≤ 6.3.4 |
𝑥
= Vulnerable software versions