First published: Wed Apr 18 2018(Updated: )
In Zulip Server versions 1.5.x, 1.6.x, and 1.7.x before 1.7.2, there was an XSS issue with muting notifications.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zulip Server | >=1.5.0<1.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-9987.
The severity level of CVE-2018-9987 is medium (6.1).
Zulip Server versions 1.5.x, 1.6.x, and 1.7.x before 1.7.2 are affected by CVE-2018-9987.
CVE-2018-9987 is an XSS issue with muting notifications in Zulip Server versions 1.5.x, 1.6.x, and 1.7.x before 1.7.2.
To fix CVE-2018-9987, you need to upgrade to Zulip Server version 1.7.2 or later.