<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1" xmlns:xhtml="http://www.w3.org/1999/xhtml">
  <url>
    <loc>https://securifyinc.com/disclosures</loc>
    <changefreq>daily</changefreq>
    <priority>0.75</priority>
    <lastmod>2022-06-02</lastmod>
  </url>
  <url>
    <loc>https://securifyinc.com/disclosures/rocketchat-unauthenticated-access-to-messages</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2021-07-02</lastmod>
  </url>
  <url>
    <loc>https://securifyinc.com/disclosures/rocketchat-monitor-messages</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2021-11-26</lastmod>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/603dc7d9cd5ee7681ca00145/1634147729319-4JJANJAH5UFBCYJVSZ1F/Screen+Shot+2021-10-13+at+10.54.24+AM.png</image:loc>
      <image:title>Security Disclosures - RocketChat - Monitor User Messages - Make it stand out</image:title>
      <image:caption>Whatever it is, the way you tell your story online can make all the difference.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/603dc7d9cd5ee7681ca00145/1634146619396-F6BNEFA55M8CPUHD5ARD/Screen+Shot+2021-10-13+at+10.35.39+AM.png</image:loc>
      <image:title>Security Disclosures - RocketChat - Monitor User Messages - User ID validation</image:title>
      <image:caption>This specific method took two parameters: rid and userID. The userID passed into the function is provided by the user rather than through the Meteor.user() session controller. Once called, the function checked if the userID was null or undefined. After the validation, it would then pull the user information.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/603dc7d9cd5ee7681ca00145/1634146917424-MAEFD2ZV3WOTTSS3G97F/Screen+Shot+2021-10-13+at+10.40.36+AM.png</image:loc>
      <image:title>Security Disclosures - RocketChat - Monitor User Messages - Room and Access validation</image:title>
      <image:caption>Next, the room validation is done by checking: If given rid is null/undefined If the rid is not null, get the room information via findOneByID canAccessRoom authorization check is called</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://securifyinc.com/disclosures/tag/rocketchat</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://securifyinc.com/disclosures/tag/nuclei-templates</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://securifyinc.com/disclosures/tag/sev%3Acritical</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://securifyinc.com/disclosures/tag/exploit</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://securifyinc.com/disclosures/tag/exploits</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://securifyinc.com/home</loc>
    <changefreq>daily</changefreq>
    <priority>1.0</priority>
    <lastmod>2021-11-26</lastmod>
  </url>
</urlset>

