Skip to content
Appaloosa Scout
MEDIUM 4.6

CVE-2025-27442

Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.

Attack vector : Adjacent network No privileges required
Show raw CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Vulnerable CPE configurations

Vendor Product Versions
zoom meeting_software_development_kit
Android
<6.3.0
zoom meeting_software_development_kit
iOS
<6.3.10
zoom rooms
Android
<6.4.0
zoom rooms
iOS
<6.4.0
zoom rooms_controller
Android
<6.4.0
zoom workplace
Android
<6.3.10
zoom workplace
iOS
<6.3.10
View on NVD ↗