CVE-2017-0896

Published
View on NVD ↗
CVSS v3
N/A
CVSS v2
4
MEDIUM
Affected
1
PROJECT

Description

Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Zulip organization even if the organization was configured to prevent this.

Zulip server and web application. Open-source team chat that helps teams stay productive and focused.
GitHubGitHub
25.4K