PT-2023-21838 · Zoom · Zoom
Published
2023-06-13
·
Updated
2024-09-19
·
CVE-2023-28599
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Zoom versions prior to 5.13.10
Description
The issue allows a malicious user to inject HTML into their display name, potentially leading a victim to a malicious website during meeting creation. This occurs when a malicious user manipulates their display name, which can cause a victim to be redirected to an unintended website.
Recommendations
For versions prior to 5.13.10, update to version 5.13.10 or later to resolve the issue. As a temporary workaround, consider restricting the ability for users to modify their display names until the update is applied.
Fix
Special Elements Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zoom