CVE-2020-15070: Zulip Server
High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.
Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres database, and chose to write a crafted custom profile field value.
Affected products
- Zulip Zulip Server: before 2.1.7 (fixed in 2.1.7)
Published 2020-08-21. Last modified 2026-06-17.