Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-05011
HistoryDec 19, 2021 - 12:00 a.m.

Zoom Client server-side request forgery vulnerability

2021-12-1900:00:00
China National Vulnerability Database
www.cnvd.org.cn
11
zoom client
video conferencing
server-side
request forgery
vulnerability
user input
validation
attackers
intranet resources
security document

EPSS

0.001

Percentile

34.5%

Zoom Client is a multi-platform video conferencing client application from Zoom, Inc. A server-side request forgery vulnerability exists in Zoom Client for Meetings prior to version 5.7.3, which stems from the product’s failure to properly validate user input and could be exploited by attackers to probe server intranet resources.

EPSS

0.001

Percentile

34.5%

Related for CNVD-2022-05011