CVE-2024-47048
25.09.2024, 01:15
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier allows stored XSS in the description and release notes of the marketplace and private apps.
Vendor | Product | Version |
---|---|---|
rocket.chat | rocket.chat | 𝑥 < 6.7.9 |
rocket.chat | rocket.chat | 6.8.0 ≤ 𝑥 < 6.8.7 |
rocket.chat | rocket.chat | 6.9.0 ≤ 𝑥 < 6.9.7 |
rocket.chat | rocket.chat | 6.10.0 ≤ 𝑥 < 6.10.6 |
rocket.chat | rocket.chat | 6.11.0 ≤ 𝑥 < 6.11.3 |
rocket.chat | rocket.chat | 6.12.0 |
rocket.chat | rocket.chat | 6.12.0:rc1 |
rocket.chat | rocket.chat | 6.12.0:rc2 |
rocket.chat | rocket.chat | 6.12.0:rc3 |
rocket.chat | rocket.chat | 6.12.0:rc4 |
rocket.chat | rocket.chat | 6.12.0:rc5 |
rocket.chat | rocket.chat | 6.12.0:rc6 |
𝑥
= Vulnerable software versions