Vulnerability CVE-2024-45621


Published: 2024-09-02

Description:
The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related to failure to use a separate browser upon encountering third-party external actions from PDF documents.

 References:
https://hackerone.com/reports/1967109
https://github.com/RocketChat/Rocket.Chat/releases/tag/6.3.4

Copyright 2026, cxsecurity.com

 

Back to Top