Home
LOW: 3.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:NDefault status
unaffected
Any version before 6.4.5
affected
Description
Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosure of information via network access.
Problem types
CWE-352 Cross-Site Request Forgery (CSRF)
Product status
Any version before 6.4.5
References
https//www.zoom.com/en/trust/security-bulletin/zsb-25025/