CVE-2017-0910

Publication date

2017-11-27 16:00:00

Family

hackerone

State

PUBLISHED

Description

In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the server create a user account on any other realm.