Medium severity6.1NVD Advisory· Published Aug 18, 2020· Updated Jun 17, 2026
CVE-2020-15926
CVE-2020-15926
Description
Rocket.Chat through 3.4.2 allows XSS where an attacker can send a specially crafted message to a channel or in a direct message to the client which results in remote code execution on the client side.
Affected products
3cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*range: <=3.4.2
- (no CPE)range: <=3.4.2
- Rocket.Chat/Rocket.Chatdescription
Patches
Vulnerability mechanics
References
3- github.com/RocketChat/Rocket.Chat/commits/developnvdPatchThird Party Advisory
- github.com/RocketChat/Rocket.Chat/pull/18356nvdPatchThird Party Advisory
- blog.redteam.pl/2020/08/rocket-chat-xss-rce-cve-2020-15926.htmlnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.