Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to DOM-based Cross-site Scripting (XSS). Attackers may be able to abuse the UpdateOTRAck method to forge a message that contains an XSS payload.
| Software | From | Fixed in |
|---|---|---|
| rocket.chat / rocket.chat | 6.12.0 | 6.12.0.x |
| rocket.chat / rocket.chat | - | 6.7.9 |
| rocket.chat / rocket.chat | 6.12.0-rc1 | 6.12.0-rc1.x |
| rocket.chat / rocket.chat | 6.12.0-rc2 | 6.12.0-rc2.x |
| rocket.chat / rocket.chat | 6.12.0-rc3 | 6.12.0-rc3.x |
| rocket.chat / rocket.chat | 6.12.0-rc4 | 6.12.0-rc4.x |
| rocket.chat / rocket.chat | 6.8.0 | 6.8.7 |
| rocket.chat / rocket.chat | 6.9.0 | 6.9.7 |
| rocket.chat / rocket.chat | 6.10.0 | 6.10.6 |
| rocket.chat / rocket.chat | 6.11.0 | 6.11.3 |
| rocket.chat / rocket.chat | 6.12.0-rc5 | 6.12.0-rc5.x |
| rocket.chat / rocket.chat | 6.12.0-rc6 | 6.12.0-rc6.x |