packetstormsecurity.com
http://packetstormsecurity.com/files/154944/Rocket.Chat-2.1.0-Cross-Site-Scripting.html CVE-2019-17220
MEDIUM
Rocket.Chat 2.1.0 - Cross-Site Scripting
Record summary
CVE-2019-17220 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.
Description
Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBRocket.Chat 2.1.0 - Cross-Site ScriptingExploitDB exploitby 3H34NNot analyzed1 file
References
5github.com
https://github.com/RocketChat/Rocket.Chat/commits/develop github.com
https://github.com/RocketChat/Rocket.Chat/releases nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-17220 nezami.me
https://www.nezami.me/