CVE-2023-3947

The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'vczapi_encrypt_decrypt' function in versions up to, and including, 4.2.1. This makes it possible for unauthenticated attackers to decrypt and view the meeting id and password.
Configurations

Configuration 1 (hide)

cpe:2.3:a:imdpen:video_conferencing_with_zoom:*:*:*:*:*:wordpress:*:*

History

02 Aug 2023, 19:37

Type Values Removed Values Added
CPE cpe:2.3:a:imdpen:video_conferencing_with_zoom:*:*:*:*:*:wordpress:*:*
CVSS v2 : unknown
v3 : 3.7
v2 : unknown
v3 : 5.3
References (MISC) https://www.wordfence.com/threat-intel/vulnerabilities/id/ba2515d9-ced0-4b49-87c4-04c8391c2608?source=cve - (MISC) https://www.wordfence.com/threat-intel/vulnerabilities/id/ba2515d9-ced0-4b49-87c4-04c8391c2608?source=cve - Third Party Advisory
References (MISC) https://plugins.trac.wordpress.org/browser/video-conferencing-with-zoom-api/trunk/includes/Helpers/Encryption.php?rev=2942302 - (MISC) https://plugins.trac.wordpress.org/browser/video-conferencing-with-zoom-api/trunk/includes/Helpers/Encryption.php?rev=2942302 - Patch
References (MISC) https://plugins.trac.wordpress.org/browser/video-conferencing-with-zoom-api/tags/4.2.1/includes/helpers.php#L546 - (MISC) https://plugins.trac.wordpress.org/browser/video-conferencing-with-zoom-api/tags/4.2.1/includes/helpers.php#L546 - Patch

26 Jul 2023, 04:24

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-26 04:15

Updated : 2024-02-05 00:01


NVD link : CVE-2023-3947

Mitre link : CVE-2023-3947

CVE.ORG link : CVE-2023-3947


JSON object : View

Products Affected

imdpen

  • video_conferencing_with_zoom
CWE

No CWE.