CVE-2024-45621
02.09.2024, 19:15
The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related to failure to use a separate browser upon encountering third-party external actions from PDF documents.
| Vendor | Product | Version |
|---|---|---|
| rocket.chat | rocket.chat | 𝑥 ≤ 6.3.4 |
𝑥
= Vulnerable software versions