CVE-2023-28325 | Rocket.Chat up to 5.x updateMessage rid improper authorization (EUVD-2023-32032)
A vulnerability was found in Rocket.Chat up to 5.x and classified as critical. The impacted element is the function updateMessage. Executing manipulation of the argument rid can lead to improper authorization.
This vulnerability is tracked as CVE-2023-28325. The attack is only possible within the local network. No exploit exists.
It is suggested to upgrade the affected component.