CVE-2023-28598: XSS
Published Jun 13, 2023
·Updated
Zoom for Linux clients prior to 5.13.10 contain an HTML injection vulnerability. If a victim starts a chat with a malicious user it could result in a Zoom application crash.
Affected Software
1 affected component
Zoom Zoom Linux<5.13.10
Event History
Jun 13, 2023
CVE Published
via MITRE·04:49 PM
Data Sourced
via MITRE·04:49 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-28598?
CVE-2023-28598 is a vulnerability found in Zoom for Linux clients prior to version 5.13.10 that allows for HTML injection.
2
How does the HTML injection vulnerability in Zoom for Linux clients work?
The HTML injection vulnerability in Zoom for Linux clients allows a malicious user to crash the Zoom application by starting a chat with a victim.
3
What is the severity of CVE-2023-28598?
The severity of CVE-2023-28598 is high, with a CVSS score of 6.5.
4
How do I know if I am affected by CVE-2023-28598?
If you are using Zoom for Linux clients prior to version 5.13.10, you are potentially affected by CVE-2023-28598.
5
How can I fix CVE-2023-28598?
To fix CVE-2023-28598, you should update your Zoom for Linux client to version 5.13.10 or later.