CVE-2020-15070
- EPSS 0.66%
- Published 21.08.2020 05:15:11
- Last modified 21.11.2024 05:04:44
Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres database, and chose to write a crafted custom profile field value.
CVE-2020-14215
- EPSS 0.2%
- Published 21.08.2020 05:15:11
- Last modified 21.11.2024 05:02:53
Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrator role to invitations.
CVE-2020-14194
- EPSS 0.2%
- Published 21.08.2020 05:15:11
- Last modified 21.11.2024 05:02:50
Zulip Server before 2.1.5 allows reverse tabnapping via a topic header link.
CVE-2020-12759
- EPSS 0.36%
- Published 21.08.2020 05:15:11
- Last modified 21.11.2024 05:00:13
Zulip Server before 2.1.5 allows reflected XSS via the Dropbox webhook.
CVE-2020-9445
- EPSS 0.36%
- Published 20.04.2020 20:15:11
- Last modified 21.11.2024 05:40:39
Zulip Server before 2.1.3 allows XSS via the modal_link feature in the Markdown functionality.
CVE-2020-9444
- EPSS 0.2%
- Published 20.04.2020 20:15:11
- Last modified 21.11.2024 05:40:39
Zulip Server before 2.1.3 allows reverse tabnabbing via the Markdown functionality.
CVE-2020-10935
- EPSS 0.3%
- Published 20.04.2020 20:15:11
- Last modified 21.11.2024 04:56:24
Zulip Server before 2.1.3 allows XSS via a Markdown link, with resultant account takeover.
CVE-2019-19775
- EPSS 0.27%
- Published 18.12.2019 04:15:15
- Last modified 21.11.2024 04:35:21
The image thumbnailing handler in Zulip Server versions 1.9.0 to before 2.0.8 allowed an open redirect that was visible to logged-in users.
CVE-2019-18933
- EPSS 0.43%
- Published 21.11.2019 23:15:13
- Last modified 21.11.2024 04:33:51
In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registered their account using social authentication (e.g., GitHub or Google SSO) in an organization that also allows password authenticati...
CVE-2019-16216
- EPSS 0.3%
- Published 18.09.2019 12:15:10
- Last modified 21.11.2024 04:30:17
Zulip server before 2.0.5 incompletely validated the MIME types of uploaded files. A user who is logged into the server could upload files of certain types to mount a stored cross-site scripting attack on other logged-in users. On a Zulip server usin...