CVE-2021-34419
Severity CVSS v4.0:
Pending analysis
Type:
CWE-74
Injection
Publication date:
11/11/2021
Last modified:
16/11/2021
Description
In the Zoom Client for Meetings for Ubuntu Linux before version 5.1.0, there is an HTML injection flaw when sending a remote control request to a user in the process of in-meeting screen sharing. This could allow meeting participants to be targeted for social engineering attacks.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:zoom:zoom_client_for_meetings:*:*:*:*:*:linux:*:* | 5.1.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page