在 8.8.0 之前版本(包括 8.7.1、8.6.2、8.5.3、8.4.6、8.3.8、8.2.8、8.1.8 以及 7.10.15)的 Rocket.Chat 中,REST API 端点 POST /api/v1/livechat/visitor 允许未认证的请求提交未经清理(unsanitized)的“name”字段,该字段用于标识即时聊天(Livechat)访客。此名称以原始形式存储,随后在 Omnichannel(全渠道)队列的侧边面板(InquireSidePanelItem.tsx)中通过 dang
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Rocket.Chat | Rocket.Chat | < 8.8.0 |
affected |
< 8.7.1 |
affected | ||
< 8.6.2 |
affected | ||
< 8.5.3 |
affected | ||
< 8.4.6 |
affected | ||
< 8.3.8 |
affected | ||
< 8.2.8 |
affected | ||
< 8.1.8 |
affected | ||
| … +1 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Rocket.Chat | Rocket.Chat | 0 ~ 8.8.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet