Vulnerabilities (CVE)

Filtered by vendor Zulip Subscribe
Filtered by product Zulip Server
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-14215 1 Zulip 1 Zulip Server 2021-07-21 5.0 MEDIUM 7.5 HIGH
Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrator role to invitations.
CVE-2020-15070 1 Zulip 1 Zulip Server 2021-07-21 6.5 MEDIUM 8.8 HIGH
Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres database, and chose to write a crafted custom profile field value.
CVE-2017-0910 1 Zulip 1 Zulip Server 2019-10-09 4.0 MEDIUM 8.8 HIGH
In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the server create a user account on any other realm.