The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'vczapi_encrypt_decrypt' function in versions up to, and including, 4.2.1. This makes it possible for unauthenticated attackers to decrypt and view the meeting id and password.
References
Configurations
Information
Published : 2023-07-26 04:15
Updated : 2023-08-02 19:37
NVD link : CVE-2023-3947
Mitre link : CVE-2023-3947
JSON object : View
Products Affected
imdpen
- video_conferencing_with_zoom
CWE
CWE-321
Use of Hard-coded Cryptographic Key
