Cross-Site Scripting Vulnerability in Zoom Workplace Apps
CVE-2025-27441

4.6MEDIUM

Key Information:

Vendor
CVE Published:
8 April 2025

Summary

A cross-site scripting vulnerability exists in Zoom Workplace Apps that may allow an unauthenticated user to exploit adjacent network access. This flaw can lead to a loss of data integrity, posing a significant risk to users and organizations relying on these applications for secure communication and collaboration. It is crucial for users to remain vigilant and update their applications to mitigate potential threats.

Affected Version(s)

Zoom Workplace Apps Windows See references.

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.