CVE-2024-53359: Zalo

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue in Zalo v23.09.01 allows attackers to obtain sensitive user information via a crafted GET request.

Affected products

  • Zalo Zalo: version 23.09.01 only

Published 2025-05-20. Last modified 2026-06-17.