.. / CVE-2020-28208

Exploit for Rocket.Chat <3.9.1 - Information Disclosure (CVE-2020-28208)

Description:

Rocket.Chat through 3.9.1 is susceptible to information disclosure. An attacker can enumerate email addresses via the password reset function and thus potentially access sensitive information, modify data, and/or execute unauthorized operations.

Nuclei Template

View the template here CVE-2020-28208.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-28208.yaml
Copy

References:

https://trovent.github.io/security-advisories/TRSA-2010-01/TRSA-2010-01.txt
http://www.openwall.com/lists/oss-security/2021/01/07/1
https://trovent.io/security-advisory-2010-01
http://packetstormsecurity.com/files/160845/Rocket.Chat-3.7.1-Email-Address-Enumeration.html
https://nvd.nist.gov/vuln/detail/CVE-2020-28208