PT-2022-16165 · Unknown · Zulip Server

Andersk

·

Published

2022-03-02

·

Updated

2022-03-09

·

CVE-2022-23656

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Zulip Server versions from June 2021 through main branch before 2022-03-01
Description The issue affects the recent topics page of Zulip Server, where an attacker could exploit a cross-site scripting vulnerability by crafting a malicious full name for their account and sending messages to a topic with multiple participants. If a victim opens an overflow tooltip including this full name, it could trigger the execution of JavaScript code controlled by the attacker.
Recommendations For Zulip Server versions from June 2021 through main branch before 2022-03-01, upgrade from main to a version 2022-03-01 or later to deploy the fix. As a temporary workaround, consider restricting access to the recent topics page or disabling the overflow tooltip feature until the upgrade is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23656
GHSA-FC77-H3JC-6MFV

Affected Products

Zulip Server