Cross-Site Scripting Vulnerability in Zulip Server by Zulip
CVE-2018-9986

6.1MEDIUM

Key Information:

Vendor

Zulip

Vendor
CVE Published:
18 April 2018

What is CVE-2018-9986?

The Zulip Server prior to version 1.7.2 is susceptible to Cross-Site Scripting (XSS) vulnerabilities through its frontend markdown processor. An attacker could exploit this flaw to execute arbitrary JavaScript code in the context of the user’s session, potentially compromising user accounts and sensitive data. Organizations using affected versions are encouraged to upgrade to the latest release to mitigate these security risks.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.