CVE-2020-28208
Rocket.Chat <3.9.1 - Information Disclosure
Record summary
CVE-2020-28208 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.9.1.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMRocket.Chat <3.9.1 - Information DisclosureCVSS 5.3
Rocket.Chat through 3.9.1 is susceptible to information disclosure. An attacker can enumerate email addresses via the password reset function and thus potentially access sensitive information, modify data, and/or execute unauthorized operations.
Impact
The vulnerability can lead to the exposure of sensitive information, such as user credentials or private conversations, potentially compromising the confidentiality of the system.
Remediation
Upgrade Rocket.Chat to version 3.9.1 or later to mitigate the information disclosure vulnerability (CVE-2020-28208).
Source: ProjectDiscovery