Rocket.Chat through 3.4.2 allows XSS where an attacker can send a specially crafted message to a channel or in a direct message to the client which results in remote code execution on the client side.
No PoCs from references.
- https://github.com/20142995/nuclei-templates
- https://github.com/alphaSeclab/sec-daily-2020
- https://github.com/cyb3r-w0lf/nuclei-template-collection
- https://github.com/doyensec/awesome-electronjs-hacking