Skip to main content

The UI Performs the Wrong Action

CVE-2023-36535

Severity High
Score 7.1/10

Summary

Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow an authenticated user to enable information disclosure via network access.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • LOW
  • HIGH
  • LOW

CWE-449 - The UI Performs the Wrong Action

The UI performs the wrong action with respect to the user's request.

References

Advisory Timeline

  • Published