← voltar
CVE-2026-24050lowCWE-79

Zulip affected by Stored XSS in user profile modal

8Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 1.1epss 0.2%
probabilidade de exploração
0.2%top 86% das CVEs
exploração observada
nãonenhuma fonte reporta
Zulip is an open-source team collaboration tool. From 5.0 to before 11.5, some administrative actions on the user profile were susceptible to stored XSS in group names or channel names. Exploiting these vulnerabilities required the user explicitly interacting with the problematic object. This vulnerability is fixed in 11.5.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U
Produtos afetados
zulip · zulip