Security Advisory
CVE-2020-15926
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
Rocket.Chat through 3.4.2 allows XSS where an attacker can send a specially crafted message to a channel or in a direct message to the client which results in remote code execution on the client side.