Vulnerabilities
Vulnerable Software
Zulip:  >> Zulip Server  >> 1.5.2  Security Vulnerabilities
Zulip Server before 2.1.3 allows reverse tabnabbing via the Markdown functionality.
CVSS Score
6.1
EPSS Score
0.002
Published
2020-04-20
Zulip Server before 2.1.3 allows XSS via the modal_link feature in the Markdown functionality.
CVSS Score
6.1
EPSS Score
0.004
Published
2020-04-20
The Markdown parser in Zulip server before 2.0.5 used a regular expression vulnerable to exponential backtracking. A user who is logged into the server could send a crafted message causing the server to spend an effectively arbitrary amount of CPU time and stall the processing of future messages.
CVSS Score
6.5
EPSS Score
0.005
Published
2019-09-18
In Zulip Server versions before 1.7.2, there were XSS issues with the frontend markdown processor.
CVSS Score
6.1
EPSS Score
0.003
Published
2018-04-18
In Zulip Server versions 1.5.x, 1.6.x, and 1.7.x before 1.7.2, there was an XSS issue with muting notifications.
CVSS Score
6.1
EPSS Score
0.003
Published
2018-04-18
In Zulip Server versions before 1.7.2, there was an XSS issue with stream names in topic typeahead.
CVSS Score
6.1
EPSS Score
0.003
Published
2018-04-18
In Zulip Server versions before 1.7.2, there was an XSS issue with user uploads and the (default) LOCAL_UPLOADS_DIR storage backend.
CVSS Score
5.4
EPSS Score
0.007
Published
2018-04-18
In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the server create a user account on any other realm.
CVSS Score
8.8
EPSS Score
0.003
Published
2017-11-27


Contact Us

Shodan ® - All rights reserved