First published: Fri Nov 29 2024(Updated: )
Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the replace_emoji_with_text function in ui_util.ts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zulip Desktop |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-36625 is classified as a high-severity vulnerability due to its potential to allow Cross Site Scripting (XSS) attacks.
To remediate CVE-2024-36625, update to the latest version of Zulip, which addresses the XSS vulnerability.
CVE-2024-36625 affects Zulip 8.3 and potentially earlier versions.
CVE-2024-36625 is a Cross Site Scripting (XSS) vulnerability.
CVE-2024-36625 arises from the replace_emoji_with_text function in the ui_util.ts file.