A vulnerability, which was classified as critical, was found in Rocket.Chat up to 6.9.x. Affected is an unknown function of the component LiveChat Message Handler. The manipulation leads to sql injection.

This vulnerability is traded as CVE-2024-37405. It is possible to launch the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.