#VU28003 Improper access control in Zulip Server
Published: May 19, 2020
Zulip Server
Zulip
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions within the "invite_by_admins_only" permission. A remote authenticated attacker can bypass implemented security restrictions and gain unauthorized access to the application.