Description
In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the server create a user account on any other realm.
References (2)
Core 2
Core References
Patch, Third Party Advisory x_refsource_confirm
https://github.com/zulip/zulip/commit/960d736e55cbb9386a68e4ee45f80581fd2a4e32
Vendor Advisory x_refsource_confirm
http://blog.zulip.org/2017/11/23/zulip-1-7-1-released/
Scores
CVSS v3
8.8
EPSS
0.0109
EPSS Percentile
61.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-287
CWE-863
Status
published
Products (2)
Zulip/Zulip Server
before 1.7.1
zulip/zulip_server
< 1.7.1
Published
Nov 27, 2017
Tracked Since
Feb 18, 2026