CVE-2019-18223: XSS
ZOOM International Call Recording 6.3.1 suffers from multiple authenticated stored XSS vulnerabilities via the phoneNumber field in the (1) User Edit or (2) User Add form, (3) name field in the Role Add form, (4) name or number field in the Edit Group form, (5) tagKey or tagValue field in the Recording Rules Configuration, or (6) txt69735:/VemailAddress/value or txt75767:/VemailFrom/value field in callrec/config.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-18223?
CVE-2019-18223 has a medium severity rating of 5.4 according to the CVSS v3.1 scoring.
How does CVE-2019-18223 impact users?
CVE-2019-18223 affects users by allowing multiple authenticated stored XSS vulnerabilities through various input fields.
How do I mitigate CVE-2019-18223?
Mitigation for CVE-2019-18223 involves validating and sanitizing user input in the affected fields.
What software is affected by CVE-2019-18223?
CVE-2019-18223 affects Eleveo Call Recording version 6.3.1.
Is there a patch available for CVE-2019-18223?
Check with the software vendor for any patches or updates addressing CVE-2019-18223.