CVE-2019-18223: XSS

Published Apr 27, 2020
·
Updated

ZOOM International Call Recording 6.3.1 suffers from multiple authenticated stored XSS vulnerabilities via the phoneNumber field in the (1) User Edit or (2) User Add form, (3) name field in the Role Add form, (4) name or number field in the Edit Group form, (5) tagKey or tagValue field in the Recording Rules Configuration, or (6) txt69735:/VemailAddress/value or txt75767:/VemailFrom/value field in callrec/config.

Affected Software

1 affected component
Eleveo Call Recording=6.3.1

Event History

Apr 27, 2020
CVE Published
via MITRE·12:48 PM
Data Sourced
via MITRE·12:48 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2019-18223?

CVE-2019-18223 has a medium severity rating of 5.4 according to the CVSS v3.1 scoring.

2

How does CVE-2019-18223 impact users?

CVE-2019-18223 affects users by allowing multiple authenticated stored XSS vulnerabilities through various input fields.

3

How do I mitigate CVE-2019-18223?

Mitigation for CVE-2019-18223 involves validating and sanitizing user input in the affected fields.

4

What software is affected by CVE-2019-18223?

CVE-2019-18223 affects Eleveo Call Recording version 6.3.1.

5

Is there a patch available for CVE-2019-18223?

Check with the software vendor for any patches or updates addressing CVE-2019-18223.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203