Security Advisory
CVE-2020-15926
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Rocket.Chat through 3.4.2 allows XSS where an attacker can send a specially crafted message to a channel or in a direct message to the client which results in remote code execution on the client side.