Zulip Server
cpe:2.3:a:zulip:zulip_server:*:*:*:*:*:*:*
- >= 1.6.0, <= 10.0
A vulnerability exists in Zulip Server versions 1.6.0 through 10.0, allowing organization administrators to delete custom profile fields from other organizations. The issue arises because the API handling the deletion does not verify that the field belongs to the same organization as the user. This flaw enables administrators to inadvertently remove fields from different organizations.
Exploitation of this vulnerability allows for unauthorized deletion of custom profile fields across organizations.
Users can upgrade to Zulip Server 10.1 to address this vulnerability. For servers hosting only one organization where new organizations cannot be created, this vulnerability is not applicable.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.