First published: Mon Apr 20 2020(Updated: )
Zulip Server before 2.1.3 allows XSS via a Markdown link, with resultant account takeover.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zulip Server | <2.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10935 is a vulnerability in Zulip Server before version 2.1.3 that allows cross-site scripting (XSS) attacks via a Markdown link, which can result in account takeover.
CVE-2020-10935 has a severity rating of medium with a CVSS score of 5.4.
CVE-2020-10935 can be exploited by tricking a user into clicking a malicious Markdown link, which can lead to cross-site scripting and potential account takeover.
Yes, a patch is available for CVE-2020-10935 in Zulip Server version 2.1.3 and later.
More information about CVE-2020-10935 can be found in the Zulip blog post [here](https://blog.zulip.org/2020/04/01/zulip-server-2-1-3-security-release/) and the Core Security advisories [here](https://www.coresecurity.com/advisories/zulip-account-takeover-stored-xss).