Cross-site Scripting Vulnerability in Zoom Clients by Zoom
CVE-2025-49462

3.5LOW

Key Information:

Vendor

Zoom

Vendor
CVE Published:
10 July 2025

What is CVE-2025-49462?

A cross-site scripting vulnerability has been identified in certain Zoom Clients prior to version 6.4.5. This flaw may allow an authenticated user to exploit network access to disclose sensitive information.

Affected Version(s)

Zoom Clients Windows 0 < 6.4.5

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-49462 : Cross-site Scripting Vulnerability in Zoom Clients by Zoom