Custom crafted message object in Meteor.Call allows remote code execution and impersonation
Critical
R
Rocket.Chat
Submitted None
Team Summary
Official summary from Rocket.Chat
The researcher found a vulnerability where an attacker could impersonate other users.
Actions:
Reported by
wreiske
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Code Injection