Rocket.Chat - Server-Side Request Forgery (SSRF)
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
PoC 已收录rocket.chat
CVSS8.6EPSS 3.2%
rocket.chat是一个开源的聊天服务器,被广泛应用于企业和组织中,提供企业级安全和合规功能,支持多种部署选项,包括云端、本地和混合。
共找到 3 条公开漏洞记录
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
Rocket.Chat 3.11, 3.12 and 3.13 contains a NoSQL injection vulnerability which allows unauthenticated access to an API endpoint. An attacker can possibly obtain sensitive information from a database, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
Rocket.Chat through 3.9.1 is susceptible to information disclosure. An attacker can enumerate email addresses via the password reset function and thus potentially access sensitive information, modify data, and/or execute unauthorized operations.