ZeroHour

CVE-2020-24582

CVSS 3.1
6.1 medium
EPSS
<1%p50
Published
()
Modified
Description

Zulip Desktop before 5.4.3 allows XSS because string escaping is mishandled during composition of the HTML for the user interface.

Vendors
zulipchat
Products
zulip desktop
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.