QID 378719
Date Published: 2023-08-10
QID 378719: Zoom Client HTML Injection Vulnerability (ZSB-23007)
Zoom provides video communications with a cloud platform for video and audio conferencing, chat, and webinars across mobile, desktop, and room systems.
Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victim to a malicious website during meeting creation.
Affected Versions:
Zoom for Windows, Linux and macOS clients before version 5.13.10
QID Detection Logic (Authenticated):
This authenticated QID detects vulnerable Zoom Client prior to version 5.13.10(Windows,Linux,MAC)
Successful exploitation of this vulnerability may allow a remote attacker to inject HTML into their display name potentially leading a victim to a malicious website during meeting creation.
CVEs related to QID 378719
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ZSB-23007 |
|