In Zulip Server prior to 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the server create a user account on any other realm.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
zulip zulip server |