Rocket.Chat是一套开源的团队聊天软件。 Rocket.Chat Mobile App 5之前版本存在安全漏洞,该漏洞源于/api/v1/chat.getThreadsList 缺乏对用户输入的清理,攻击者利用该漏洞可以通过 Mongo DB 注入将私有线程消息泄露给未经授权的用户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Rocket.Chat | Fixed in version 5.0> | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-35893 | Insyde InsydeH2O 输入验证错误漏洞 | |
| CVE-2022-35246 | Rocket.Chat 安全漏洞 | |
| CVE-2022-32220 | Rocket.Chat 信息泄露漏洞 | |
| CVE-2022-35249 | Rocket.Chat 信息泄露漏洞 | |
| CVE-2022-35250 | Rocket.Chat 安全漏洞 | |
| CVE-2022-35248 | Rocket.Chat 授权问题漏洞 | |
| CVE-2022-40359 | Google KFM 跨站脚本漏洞 | |
| CVE-2022-40358 | Pydio 跨站脚本漏洞 | |
| CVE-2022-36338 | Insyde InsydeH2O 安全漏洞 | |
| CVE-2022-35099 | SWFTools 缓冲区错误漏洞 | |
| CVE-2022-35251 | Rocket.Chat 跨站脚本漏洞 | |
| CVE-2022-32218 | Rocket.Chat 信息泄露漏洞 | |
| CVE-2022-32226 | Rocket.Chat 输入验证错误漏洞 | |
| CVE-2022-32227 | Rocket.Chat 信息泄露漏洞 | |
| CVE-2022-32228 | Rocket.Chat 安全漏洞 | |
| CVE-2022-35247 | Rocket.Chat 安全漏洞 | |
| CVE-2022-30124 | Rocket.Chat 授权问题漏洞 | |
| CVE-2022-32211 | Rocket.Chat SQL注入漏洞 | |
| CVE-2022-32217 | Rocket.Chat 日志信息泄露漏洞 | |
| CVE-2022-32219 | Rocket.Chat 信息泄露漏洞 |
Showing top 20 of 79 CVEs. View all on vendor page → →
No comments yet