Vulnerability Database
Blog
FAQ
Docs
CVE-2018-9990
See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2018-9990
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-9990.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-9990
Published
2018-04-18T08:29:00Z
Modified
2024-09-02T23:31:16Z
Severity
6.1 (Medium)
CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS Calculator
Summary
[none]
Details
In Zulip Server versions before 1.7.2, there was an XSS issue with stream names in topic typeahead.
References
https://blog.zulip.org/2018/04/12/zulip-1-7-2-released/
Affected packages
Git
/
github.com/zulip/zulip
Affected ranges
Type
GIT
Repo
https://github.com/zulip/zulip
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Fixed
6bad5b661695f8796ce7e9a50f588b4da34e27c4
CVE-2018-9990 - OSV