First published: Wed Apr 18 2018(Updated: )
In Zulip Server versions before 1.7.2, there were XSS issues with the frontend markdown processor.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zulip Server | <1.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-9986 is medium with a CVSS score of 6.1.
The affected software for CVE-2018-9986 is Zulip Server versions before 1.7.2.
CVE-2018-9986 is a Cross-Site Scripting (XSS) vulnerability in Zulip Server versions before 1.7.2.
To fix CVE-2018-9986, you should upgrade to Zulip Server version 1.7.2 or later.
You can find more information about CVE-2018-9986 at the following link: [https://blog.zulip.org/2018/04/12/zulip-1-7-2-released/](https://blog.zulip.org/2018/04/12/zulip-1-7-2-released/)