ZeroHour

CVE-2022-0384

PoC
CVSS 3.1
4.3 medium
EPSS
1%p61
Published
()
Modified
Description

The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its vczapi_get_wp_users AJAX action, allowing any authenticated users, such as subscriber to download the list of email addresses registered on the blog

Vendors
imdpen
Products
video conferencing with zoom
Ecosystems
WordPress
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.