In Zulip Server versions before 1.7.2, there were XSS issues with the frontend markdown processor.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://blog.zulip.org/2018/04/12/zulip-1-7-2-released/ | release notes vendor advisory |