5.3
CVSSv3

CVE-2023-28359

Published: 11/05/2023 Updated: 22/05/2023
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A NoSQL injection vulnerability has been identified in the listEmojiCustom method call within Rocket.Chat. This can be exploited by unauthenticated users when there is at least one custom emoji uploaded to the Rocket.Chat instance. The vulnerability causes a delay in the server response, with the potential for limited impact.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rocket.chat rocket.chat