mirror of
https://github.com/zulip/zulip.git
synced 2025-11-05 14:35:27 +00:00
An attacker could maliciously craft a full name for their account and send messages to a topic with several participants; a victim who then opens an overflow tooltip including this full name on the recent topics page could trigger execution of JavaScript code controlled by the attacker. Signed-off-by: Anders Kaseorg <anders@zulip.com>
25 KiB
25 KiB