Medium severity6.1NVD Advisory· Published Oct 21, 2019· Updated Jun 17, 2026
CVE-2019-17220
CVE-2019-17220
Description
Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*range: <2.1.0
- (no CPE)range: <2.1.0
- Rocket.Chat/Rocket.Chatdescription
Patches
Vulnerability mechanics
References
4- github.com/RocketChat/Rocket.Chat/commits/developnvdPatchThird Party Advisory
- www.nezami.menvdExploitThird Party Advisory
- github.com/RocketChat/Rocket.Chat/releasesnvdRelease NotesThird Party Advisory
- packetstormsecurity.com/files/154944/Rocket.Chat-2.1.0-Cross-Site-Scripting.htmlnvd
News mentions
0No linked articles in our index yet.