First published: Wed Apr 18 2018(Updated: )
In Zulip Server versions before 1.7.2, there was an XSS issue with user uploads and the (default) LOCAL_UPLOADS_DIR storage backend.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zulip Server | <1.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9999 is a Cross-Site Scripting (XSS) vulnerability in Zulip Server versions before 1.7.2.
CVE-2018-9999 has a severity score of 5.4, which is considered medium.
Zulip Server versions up to but not including 1.7.2 are affected by CVE-2018-9999.
CVE-2018-9999 is categorized under CWE-79, which is Cross-Site Scripting (XSS).
Yes, Zulip Server version 1.7.2 or later includes a fix for CVE-2018-9999. It is recommended to upgrade to this version or a newer one.