CVE Published: 27/11/2017 |
CVE Updated: 17/09/2024 |
CVE Year: 2017 Source: hackerone |
Vendor: Zulip |
Product: Zulip Server Status : PUBLISHED
CVE-2017-0910 Description
In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the server create a user account on any other realm.