PT-2023-24203 · Unknown · Zulip Server

Highandersk

·

Published

2023-05-30

·

Updated

2023-11-06

·

CVE-2023-33186

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Zulip Server versions 7.0-beta1 through 7.0-beta2 and the main development branch from May 2, 2023 and later
Description The issue is related to a cross-site scripting vulnerability in tooltips on the message feed. An attacker who can send messages could maliciously craft a topic for the message, such that a victim who hovers the tooltip for that topic in their message feed triggers execution of JavaScript code controlled by the attacker.
Recommendations For Zulip Server versions 7.0-beta1 and 7.0-beta2, consider disabling tooltips on the message feed until a patch is available. For the main development branch from May 2, 2023 and later, restrict access to the message feed or avoid hovering over tooltips for topics from untrusted sources until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-33186
GHSA-4R83-8F94-HRPH

Affected Products

Zulip Server