Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.
According to the CVSS metric, successful exploitation of this vulnerability could lead to loss of confidentiality (C:H)? What does that mean for this vulnerability? Successful exploitation of this vulnerability allows an attacker to impersonate another user and access information based on the victim user's permission levels.
Ofek Levin Enclave with <a href="https://enclave.ai/">Enclave AI</a>