Cross-Site Scripting in Zulip Server Affects User Accounts
CVE-2020-10935
5.4MEDIUM
What is CVE-2020-10935?
Zulip Server versions prior to 2.1.3 are susceptible to a Cross-Site Scripting (XSS) vulnerability that arises when processing Markdown links. This flaw can be exploited by an attacker to execute arbitrary JavaScript in the context of a victim's session, potentially leading to account takeover. Users are encouraged to upgrade to the latest version to mitigate this risk. For further details, refer to the official security release and advisories.