Video Conferencing with Zoom <= 4.2.1 - Sensitive Information Exposure

2023-07-25 00:00
István Márton

Strategic Overview

Status
Patched in 4.2.2
Affected Version<= 4.2.1
CVSS3.7Low
CVECVE-2023-3947
View all Video Conferencing with Zoom vulnerabilities

Vulnerability Overview

The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'vczapi_encrypt_decrypt' function in versions up to, and including, 4.2.1. This makes it possible for unauthenticated attackers to decrypt and view the meeting id and password.

Technical Analysis

REMEDIATION: Update to version 4.2.2, or a newer patched version --- IDENTIFIER: CWE-321 (Use of Hard-coded Cryptographic Key) The product uses a hard-coded, unchangeable cryptographic key.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C