It is possible to elevate privileges for any authenticated user to view permissions matrix and view Direct messages without appropriate permissions.

Disclosed: 2022-09-22 16:00:58 By garretby To rocket_chat
Medium
Vulnerability Details
No vulnerability description provided or it is restricted.
Actions
View on HackerOne
Report Stats
  • Report ID: 917946
  • State: Closed
  • Substate: resolved
  • Upvotes: 3
Share this report