CVE-2024-53359

An issue in Zalo v23.09.01 allows attackers to obtain sensitive user information via a crafted GET request.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zalo:zalo:23.09.01:*:*:*:*:*:*:*

History

12 Jun 2025, 16:21

Type Values Removed Values Added
Summary
  • (es) Un problema en ZALO V23.09.01 permite a los atacantes obtener información confidencial del usuario a través de una solicitud manipulada.
References () https://github.com/crysalix4/CVE/tree/main/CVE-2024-53359 - () https://github.com/crysalix4/CVE/tree/main/CVE-2024-53359 - Exploit
References () https://www.linkedin.com/in/le-anh-truong/ - () https://www.linkedin.com/in/le-anh-truong/ - Not Applicable
First Time Zalo zalo
Zalo
CPE cpe:2.3:a:zalo:zalo:23.09.01:*:*:*:*:*:*:*

20 May 2025, 18:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-200

20 May 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-20 14:15

Updated : 2025-06-12 16:21


NVD link : CVE-2024-53359

Mitre link : CVE-2024-53359

CVE.ORG link : CVE-2024-53359


JSON object : View

Products Affected

zalo

  • zalo
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor