PT-2022-16165 · Unknown · Zulip Server
Andersk
·
Published
2022-03-02
·
Updated
2022-03-09
·
CVE-2022-23656
CVSS v3.1
4.6
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Zulip Server versions from June 2021 through main branch before 2022-03-01
Description
The issue affects the recent topics page of Zulip Server, where an attacker could exploit a cross-site scripting vulnerability by crafting a malicious full name for their account and sending messages to a topic with multiple participants. If a victim opens an overflow tooltip including this full name, it could trigger the execution of JavaScript code controlled by the attacker.
Recommendations
For Zulip Server versions from June 2021 through main branch before 2022-03-01, upgrade from main to a version 2022-03-01 or later to deploy the fix. As a temporary workaround, consider restricting access to the recent topics page or disabling the overflow tooltip feature until the upgrade is applied.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zulip Server