2020-08-21 07:15:00 2020-08-26 18:06:00

Zulip Server before 2.1.5 allows reflected XSS via the Dropbox webhook.

Vector

NETWORK

Complexity

MEDIUM

Authentication

NONE

Confidentiality

NONE

Integrity

PARTIAL

Availability

NONE