An issue in Zalo v23.09.01 allows attackers to obtain sensitive user information via a crafted GET request.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.linkedin.com/in/le-anh-truong/ | not applicable |
https://github.com/crysalix4/CVE/tree/main/CVE-2024-53359 | exploit |