Vulnerability Details CVE-2020-24582
Zulip Desktop before 5.4.3 allows XSS because string escaping is mishandled during composition of the HTML for the user interface.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 57.4%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2020-24582
-
cpe:2.3:a:zulipchat:zulip_desktop:0.0.1
-
cpe:2.3:a:zulipchat:zulip_desktop:0.5.1
-
cpe:2.3:a:zulipchat:zulip_desktop:0.5.10
-
cpe:2.3:a:zulipchat:zulip_desktop:0.5.2
-
cpe:2.3:a:zulipchat:zulip_desktop:0.5.3
-
cpe:2.3:a:zulipchat:zulip_desktop:0.5.4
-
cpe:2.3:a:zulipchat:zulip_desktop:0.5.6
-
cpe:2.3:a:zulipchat:zulip_desktop:0.5.7
-
cpe:2.3:a:zulipchat:zulip_desktop:0.5.8
-
cpe:2.3:a:zulipchat:zulip_desktop:0.5.9
-
cpe:2.3:a:zulipchat:zulip_desktop:1.0.0
-
cpe:2.3:a:zulipchat:zulip_desktop:1.1.0
-
cpe:2.3:a:zulipchat:zulip_desktop:1.2.0
-
cpe:2.3:a:zulipchat:zulip_desktop:1.3.0
-
cpe:2.3:a:zulipchat:zulip_desktop:1.4.0
-
cpe:2.3:a:zulipchat:zulip_desktop:1.5.0
-
cpe:2.3:a:zulipchat:zulip_desktop:1.6.0
-
cpe:2.3:a:zulipchat:zulip_desktop:1.7.0
-
cpe:2.3:a:zulipchat:zulip_desktop:1.8.1
-
cpe:2.3:a:zulipchat:zulip_desktop:1.8.2
-
cpe:2.3:a:zulipchat:zulip_desktop:1.9.0
-
cpe:2.3:a:zulipchat:zulip_desktop:2.0.0
-
cpe:2.3:a:zulipchat:zulip_desktop:2.2.0
-
cpe:2.3:a:zulipchat:zulip_desktop:2.3.1
-
cpe:2.3:a:zulipchat:zulip_desktop:2.3.2
-
cpe:2.3:a:zulipchat:zulip_desktop:2.3.3
-
cpe:2.3:a:zulipchat:zulip_desktop:2.3.4
-
cpe:2.3:a:zulipchat:zulip_desktop:2.3.5
-
cpe:2.3:a:zulipchat:zulip_desktop:2.3.6
-
cpe:2.3:a:zulipchat:zulip_desktop:2.3.7
-
cpe:2.3:a:zulipchat:zulip_desktop:2.3.8
-
cpe:2.3:a:zulipchat:zulip_desktop:2.3.82
-
cpe:2.3:a:zulipchat:zulip_desktop:2.5.0
-
cpe:2.3:a:zulipchat:zulip_desktop:3.0.0
-
cpe:2.3:a:zulipchat:zulip_desktop:3.1.0
-
cpe:2.3:a:zulipchat:zulip_desktop:4.0.0
-
cpe:2.3:a:zulipchat:zulip_desktop:4.0.2
-
cpe:2.3:a:zulipchat:zulip_desktop:4.0.3
-
cpe:2.3:a:zulipchat:zulip_desktop:5.0.0
-
cpe:2.3:a:zulipchat:zulip_desktop:5.1.0
-
cpe:2.3:a:zulipchat:zulip_desktop:5.2.0