Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Nov 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:zulip:zulip:8.3:*:*:*:*:*:*:* |
Fri, 29 Nov 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Fri, 29 Nov 2024 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the construct_copy_div function in copy_and_paste.js. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-29T18:17:17.138Z
Reserved: 2024-05-30T00:00:00.000Z
Link: CVE-2024-36624
Updated: 2024-11-29T18:16:53.388Z
Status : Analyzed
Published: 2024-11-29T18:15:08.440
Modified: 2025-11-25T13:49:35.170
Link: CVE-2024-36624
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:14:56Z