Video Conferencing with Zoom <= 3.8.16 - E-mail Address Disclosure

2022-02-14 00:00
Krzysztof Zając

Strategic Overview

Status
Patched in 3.8.17
Affected Version< 3.8.17
CVSS4.3Medium
CVECVE-2022-0384
View all Video Conferencing with Zoom vulnerabilities

Vulnerability Overview

The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its vczapi_get_wp_users AJAX action, allowing any authenticated users, such as subscriber to download the list of email addresses registered on the blog

Technical Analysis

REMEDIATION: Update to version 3.8.17, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C