CVE-2019-18223 Information
Feb 14, 2021
cve
Description
ZOOM International Call Recording 6.3.1 suffers from multiple authenticated stored XSS vulnerabilities via the phoneNumber field in the (1) User Edit or (2) User Add form (3) name field in the Role Add form (4) name or number field in the Edit Group form (5) tagKey or tagValue field in the Recording Rules Configuration or (6) txt_69735:/VemailAddress/value or txt_75767:/VemailFrom/value field in callrec/config.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Reference
https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-18223-XSS-ZoomCallRecording
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Share on: