CVE-2022-21830: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
(updated )
A blind self XSS vulnerability exists in RocketChat LiveChat <v1.9 that could allow an attacker to trick a victim pasting malicious code in their chat instance.
References
Detect and mitigate CVE-2022-21830 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →