CVE-2022-23656 is a cross-site scripting (XSS) vulnerability affecting the Zulip Server main development branch from June 2021 onwards. An authenticated attacker can craft a malicious full name, which, when viewed in an overflow tooltip on the recent topics page by a victim, allows for arbitrary JavaScript execution. This vulnerability has a CVSS score of 5.4 (Medium), indicating a low-complexity attack requiring user interaction and leading to limited confidentiality and integrity impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2021-06-03, < 2022-03-01CPE matchmatch criteria | cpe:2.3:a:zulip:zulip_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.