Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Tom Daff

#37925of 56,330
7.5Total CVSS
Vulnerabilities · 1
PT-2020-13940
7.5
2020-08-21
Zulip · Zulip Server · CVE-2020-14215
**Name of the Vulnerable Software and Affected Versions** Zulip Server versions prior to 2.1.5 **Description** The issue is related to Incorrect Access Control. Specifically, the `0198 preregistrationuser invited as` addition grants the administrator role to invitations, which is not intended. **Recommendations** For versions prior to 2.1.5, update to version 2.1.5 or later to resolve the issue.