Skip to content

Instantly share code, notes, and snippets.

@1047524396
Last active November 29, 2024 04:39
Show Gist options
  • Select an option

  • Save 1047524396/64720d2aa5afd943eb7e5a1ed4808ad6 to your computer and use it in GitHub Desktop.

Select an option

Save 1047524396/64720d2aa5afd943eb7e5a1ed4808ad6 to your computer and use it in GitHub Desktop.
CVE-2024-36624
[CVE ID]
CVE-2024-36624
[PRODUCT]
zulip
[VERSION]
8.3
[PROBLEM TYPE]
Cross Site Scripting (XSS)
[DESCRIPTION]
Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the construct_copy_div function in copy_and_paste.js.
[PATCH LINK]
https://github.com/zulip/zulip/commit/e1029b59ede0c4f314c367ffa1ba2904ffaf6768
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment