← Back

CVE-2025-46786

nvd nist
Published: May 14, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network access.

Affected (21)

6 products
Meeting Software Development Kit
Rooms
Rooms Controller
Workplace
Workplace Desktop
Configuration A
21 vulnerable
Vulnerable SoftwareAffected Versions
Zoom
Before 6.4.0
Before 6.4.0
Before 6.4.0
Before 6.4.0
Before 6.4.0
Zoom
Before 6.4.0
Before 6.4.0
Before 6.4.0
Before 6.4.0
Zoom
Before 6.4.0
Before 6.4.0
Before 6.4.0
Before 6.4.0
Zoom
Before 6.4.0
Before 6.4.0
Zoom
Before 6.4.0
Before 6.4.0
Before 6.4.0
Zoom
Before 6.1.17
From 6.1.18 to 6.2.13
From 6.2.14 to 6.3.10

References (1)

Source: security@zoom.us
Vendor Advisory

Timeline

No history available yet.