CVE-2020-12759

Zulip Server before 2.1.5 allows reflected XSS via the Dropbox webhook.