Cross-Site Scripting Vulnerability in Zulip Server from Zulip Inc.
CVE-2018-9999
5.4MEDIUM
What is CVE-2018-9999?
In Zulip Server versions prior to 1.7.2, a vulnerability existed that allowed attackers to exploit user uploads within the (default) LOCAL_UPLOADS_DIR storage backend. This cross-site scripting (XSS) issue can enable unauthorized script execution within the context of a user’s session, posing significant risks to data integrity and confidentiality. Administrators are advised to update to the latest version to mitigate this risk.