The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly parse XML stanzas in XMPP messages. This can allow a malicious user to break out of the current XMPP message context and create a new message context to have the receiving users client perform a variety of actions.This issue could be used in a more sophisticated attack to forge XMPP messages from the server.
Source: MITRE
Published: 2022-05-18
Updated: 2022-05-27
Type: CWE-91
Base Score: 5.5
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N
Impact Score: 4.9
Exploitability Score: 8
Severity: MEDIUM
Base Score: 8.1
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Impact Score: 5.2
Exploitability Score: 2.8
Severity: HIGH