Medium severity5.4NVD Advisory· Published Jan 26, 2021· Updated Jun 17, 2026
CVE-2020-8292
CVE-2020-8292
Description
Rocket.Chat server before 3.9.0 is vulnerable to a self cross-site scripting (XSS) vulnerability via the drag & drop functionality in message boxes.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*range: <3.9.0
- (no CPE)range: <3.9.0
- Rocket.Chat/Rocket.Chat serverdescription
Patches
Vulnerability mechanics
References
2- hackerone.com/reports/962902nvdExploitThird Party Advisory
- docs.rocket.chat/guides/security/security-updatesnvdVendor Advisory
News mentions
0No linked articles in our index yet.