Cross-Site Scripting Vulnerability in Zulip Server by Zulip
CVE-2020-9445
6.1MEDIUM
What is CVE-2020-9445?
An XSS vulnerability was identified in the Zulip Server that allows attackers to exploit the modal_link feature within its Markdown functionality. This flaw can enable unauthorized script execution in users' browsers, potentially leading to data leakage and session hijacking. Users are advised to upgrade to version 2.1.3 or later to mitigate the risk.