S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-28208 Scanner

Detects 'User Enumeration' vulnerability in Rocket.Chat affects v. through 3.9.1..

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
2
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-28208
5.3
CVSS

An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.9.1.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Rocket.Chat is a popular open-source platform that allows users to communicate in real-time through chat, voice, video, and file sharing. It is widely used by businesses, organizations, and communities for various purposes, such as team collaboration, customer communication, and online education. With its customizable features, Rocket.Chat provides users with a flexible and secure communication platform that can be tailored to fit their specific needs. 

However, a critical vulnerability has been identified in the password reset function of Rocket.Chat version 3.9.1 and earlier. The vulnerability, identified as CVE-2020-28208, allows an attacker to enumerate email addresses by exploiting a flaw in the password reset functionality. This means that an attacker can obtain a list of all the registered email addresses on the platform, which can be used for further attacks such as phishing and social engineering. 

Exploiting this vulnerability can be particularly dangerous for businesses and organizations that use Rocket.Chat for sensitive communications, such as confidential client information or financial data. An attacker could leverage the email address list to launch targeted attacks against these organizations, potentially leading to data breaches and financial losses. In addition, a successful attack could damage the reputation and trust of the affected organization among its clients and partners. 

Thanks to the pro features of the s4e.io platform, users can easily and quickly identify vulnerabilities in their digital assets and take proactive measures to secure them. The platform offers a comprehensive vulnerability assessment that covers web applications, mobile apps, APIs, and cloud infrastructure. With its user-friendly interface and actionable insights, s4e.io empowers users to secure their digital assets against a range of threats, including the CVE-2020-28208 vulnerability in Rocket.Chat.

 

REFERENCES

Solution Advice

To protect against the CVE-2020-28208 vulnerability in Rocket.Chat, users can take the following precautions:

  • Upgrade to the latest version of Rocket.Chat, which includes a fix for the vulnerability.
  • Limit the number of password reset attempts to prevent brute-force attacks.
  • Use strong passwords and enable two-factor authentication for added security.
  • Monitor login activities and alert users of any suspicious activity.
  • Educate users on phishing and social engineering tactics and encourage them to report any suspicious emails or messages.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.