mirror of
https://github.com/zulip/zulip.git
synced 2025-11-09 08:26:11 +00:00
An attacker could maliciously craft a full name for their account and send messages to a topic with several participants; a victim who then opens an overflow tooltip including this full name on the recent topics page could trigger execution of JavaScript code controlled by the attacker. Signed-off-by: Anders Kaseorg <anders@zulip.com>
8.0 KiB
8.0 KiB