Sploitus

CVE-2022-23656

No indexed exploits for CVE-2022-23656 yet

Zulip is an open source team chat app. The `main` development branch of Zulip Server from June 2021 and later is vulnerable to a cross-site scripting vulnerability on the recent topics page. An attacker could maliciously craft a full name for their account and send messages to a topic with several participants; a victim who then opens an overflow tooltip including this full name on the recent topics page could trigger execution of JavaScript code controlled by the attacker. Users running a Zulip server from the main branch should upgrade from main (2022-03-01 or later) again to deploy this fix.

Affected products
Zulip Server
Zulip Zulip Server
< 2022-03-01
Fix
Available
CVSS 3.1
5.4 MEDIUM
EPSS
0.6% (46th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2022-03-02
CVE-2022-23656 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2022-23656 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2022-23656 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.