An improper authorization vulnerability exists in Rocket...
Moderate severity
Unreviewed
Published
May 12, 2023
to the GitHub Advisory Database
•
Updated Jan 27, 2025
Description
Published by the National Vulnerability Database
May 11, 2023
Published to the GitHub Advisory Database
May 12, 2023
Last updated
Jan 27, 2025
An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the updateMessage method that only checks whether the user is allowed to edit message in the target room.
References