5.3
CVSSv3

CVE-2020-28208

Published: 08/01/2021 Updated: 01/02/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An email address enumeration vulnerability exists in the password reset function of Rocket.Chat up to and including 3.9.1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rocket.chat rocket.chat

Exploits

RocketChat versions 371 and below suffers from an email address enumeration vulnerability ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: Trovent Security Advisory 2010-01 [updated] / CVE-2020-28208: RocketChat email address enumeration vulnerability ...