CVE-2024-53359 is a high-severity information disclosure vulnerability in Zalo v23.09.01, allowing unauthenticated attackers to obtain sensitive user data through a crafted GET request. With a CVSS score of 7.5, this network-exploitable flaw requires no user interaction and has a high impact on confidentiality. While there are no known public exploits, Metasploit modules, or significant community discussion, organizations using Zalo v23.09.01 should prioritize patching to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
23.09.01CPE matchmatch criteria | cpe:2.3:a:zalo:zalo:23.09.01:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.