Cross-Site Scripting Vulnerability in Zulip Server by Zulip
CVE-2018-9986
6.1MEDIUM
What is CVE-2018-9986?
The Zulip Server prior to version 1.7.2 is susceptible to Cross-Site Scripting (XSS) vulnerabilities through its frontend markdown processor. An attacker could exploit this flaw to execute arbitrary JavaScript code in the context of the user’s session, potentially compromising user accounts and sensitive data. Organizations using affected versions are encouraged to upgrade to the latest release to mitigate these security risks.