Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-32269 | Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victim to a malicious website during meeting creation. |
| Link | Providers |
|---|---|
| https://explore.zoom.us/en/trust/security/security-bulletin/ |
|
Thu, 02 Jan 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 19 Sep 2024 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victim to a malicious website during meeting creation. | Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victim to a malicious website during meeting creation. |
| Weaknesses | CWE-79 |
Status: PUBLISHED
Assigner: Zoom
Published:
Updated: 2025-01-02T20:02:33.519Z
Reserved: 2023-03-17T13:27:32.368Z
Link: CVE-2023-28599
Updated: 2024-08-02T13:43:23.583Z
Status : Modified
Published: 2023-06-13T17:15:14.537
Modified: 2024-11-21T07:55:38.560
Link: CVE-2023-28599
No data.
OpenCVE Enrichment
No data.
EUVD