Zulip Server before 2.1.5 allows reverse tabnapping via a topic header link.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zulip_server | Zulip | * | 2.1.5 (excluding) |