CVEs Blog | G5 Cyber Security

CVE-2020-24582 – Zulip Desktop before 5.4.3 allows XSS because string escaping is mishandl

Zulip Desktop before 5.4.3 allows XSS because string escaping is mishandled during composition of the HTML for the user interface.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24582

Reference (s):

Exit mobile version