CVE-2025-30368

CVSS 3.1 Score 2.7 of 10 (low)

Details

Published Mar 31, 2025
Updated: Apr 1, 2025
CWE ID 566

Summary

CVE-2025-30368 is a vulnerability affecting Zulip, an open-source team collaboration tool. The issue lies in the API for deleting an organization export, which was intended to be accessible only to organization administrators. However, the handler failed to verify that the field belonged to the same organization as the user, enabling an administrator from a different organization to incorrectly delete an export. This security flaw has been rectified in Zulip Server 10.1.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share