Record summary

CVE-2020-28208 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.9.1.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMRocket.Chat <3.9.1 - Information DisclosureCVSS 5.3

Rocket.Chat through 3.9.1 is susceptible to information disclosure. An attacker can enumerate email addresses via the password reset function and thus potentially access sensitive information, modify data, and/or execute unauthorized operations.

Impact

The vulnerability can lead to the exposure of sensitive information, such as user credentials or private conversations, potentially compromising the confidentiality of the system.

Remediation

Upgrade Rocket.Chat to version 3.9.1 or later to mitigate the information disclosure vulnerability (CVE-2020-28208).

WeaknessesCWE-203
Authorspdteam
Template tagscvecve2020packetstormrocketchatrocket.chatvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
Shodan: http.title:"rocket.chat"
FOFA: title="rocket.chat"
Google: intitle:"rocket.chat"

Source: ProjectDiscovery

References

9