Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Tom Daff

#37213of 53,632
7.5Total CVSS
Vulnerabilities · 1
PT-2020-13940
7.5
2020-08-21
Zulip · Zulip Server · CVE-2020-14215
**Name of the Vulnerable Software and Affected Versions** Zulip Server versions prior to 2.1.5 **Description** The issue is related to Incorrect Access Control. Specifically, the `0198 preregistrationuser invited as` addition grants the administrator role to invitations, which is not intended. **Recommendations** For versions prior to 2.1.5, update to version 2.1.5 or later to resolve the issue.