Vulnerabilities
Vulnerable Software
Zulip Desktop before 5.4.3 allows XSS because string escaping is mishandled during composition of the HTML for the user interface.
CVSS Score
6.1
EPSS Score
0.004
Published
2020-09-10
Zulip Desktop before 4.0.3 loaded untrusted content in an Electron webview with web security disabled, which can be exploited for XSS in a number of ways. This especially affects Zulip Desktop 2.3.82.
CVSS Score
6.1
EPSS Score
0.004
Published
2020-03-18


Contact Us

Shodan ® - All rights reserved