Zulip Server before 2.1.5 allows reverse tabnapping via a topic header link.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://blog.zulip.com/2020/06/17/zulip-server-2-1-5-security-release/ | release notes vendor advisory |