{"api_version":"1","generated_at":"2026-07-24T19:34:34+00:00","cve":"CVE-2012-1213","urls":{"html":"https://cve.report/CVE-2012-1213","api":"https://cve.report/api/cve/CVE-2012-1213.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-1213","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-1213"},"summary":{"title":"CVE-2012-1213","description":"Cross-site scripting (XSS) vulnerability in zimbra/h/calendar in Zimbra Web Client in Zimbra Collaboration Suite (ZCS) 6.x before 6.0.15 and 7.x before 7.1.3 allows remote attackers to inject arbitrary web script or HTML via the view parameter.","state":"PUBLISHED","assigner":"mitre","published_at":"2012-02-24 13:55:07","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/73168","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/73168","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.zimbra.com/show_bug.cgi?id=63849","name":"https://bugzilla.zimbra.com/show_bug.cgi?id=63849","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bug 63849 – HTTP Request to show Day view of Standard HTML Calendar is not sanitized","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/51974","name":"http://www.securityfocus.com/bid/51974","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Zimbra 'view' Parameter Cross Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://st2tea.blogspot.com/2012/02/zimbra-cross-site-scripting.html","name":"http://st2tea.blogspot.com/2012/02/zimbra-cross-site-scripting.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"st2tea: Zimbra Cross Site Scripting","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.org/files/109710/Zimbra-Cross-Site-Scripting.html","name":"http://packetstormsecurity.org/files/109710/Zimbra-Cross-Site-Scripting.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Zimbra Cross Site Scripting ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-1213","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-1213","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"1213","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zimbra","cpe5":"zimbra","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T18:53:36.394Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"zimbra-view-xss(73168)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/73168"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://packetstormsecurity.org/files/109710/Zimbra-Cross-Site-Scripting.html"},{"name":"51974","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/51974"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.zimbra.com/show_bug.cgi?id=63849"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://st2tea.blogspot.com/2012/02/zimbra-cross-site-scripting.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-02-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in zimbra/h/calendar in Zimbra Web Client in Zimbra Collaboration Suite (ZCS) 6.x before 6.0.15 and 7.x before 7.1.3 allows remote attackers to inject arbitrary web script or HTML via the view parameter."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-11-17T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"zimbra-view-xss(73168)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/73168"},{"tags":["x_refsource_MISC"],"url":"http://packetstormsecurity.org/files/109710/Zimbra-Cross-Site-Scripting.html"},{"name":"51974","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/51974"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.zimbra.com/show_bug.cgi?id=63849"},{"tags":["x_refsource_MISC"],"url":"http://st2tea.blogspot.com/2012/02/zimbra-cross-site-scripting.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2012-1213","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in zimbra/h/calendar in Zimbra Web Client in Zimbra Collaboration Suite (ZCS) 6.x before 6.0.15 and 7.x before 7.1.3 allows remote attackers to inject arbitrary web script or HTML via the view parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"zimbra-view-xss(73168)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/73168"},{"name":"http://packetstormsecurity.org/files/109710/Zimbra-Cross-Site-Scripting.html","refsource":"MISC","url":"http://packetstormsecurity.org/files/109710/Zimbra-Cross-Site-Scripting.html"},{"name":"51974","refsource":"BID","url":"http://www.securityfocus.com/bid/51974"},{"name":"https://bugzilla.zimbra.com/show_bug.cgi?id=63849","refsource":"CONFIRM","url":"https://bugzilla.zimbra.com/show_bug.cgi?id=63849"},{"name":"http://st2tea.blogspot.com/2012/02/zimbra-cross-site-scripting.html","refsource":"MISC","url":"http://st2tea.blogspot.com/2012/02/zimbra-cross-site-scripting.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2012-1213","datePublished":"2012-02-20T19:00:00.000Z","dateReserved":"2012-02-20T00:00:00.000Z","dateUpdated":"2024-08-06T18:53:36.394Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2012-02-24 13:55:07","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:zimbra:zimbra:*:*:*:*:*:*:*:*","matchCriteriaId":"56F19372-2066-431F-B96E-D4D89BCB67BB"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"1213","Ordinal":"1","Title":"CVE-2012-1213","CVE":"CVE-2012-1213","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"1213","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in zimbra/h/calendar in Zimbra Web Client in Zimbra Collaboration Suite (ZCS) 6.x before 6.0.15 and 7.x before 7.1.3 allows remote attackers to inject arbitrary web script or HTML via the view parameter.","Type":"Description","Title":"CVE-2012-1213"},{"CveYear":"2012","CveId":"1213","Ordinal":"2","NoteData":"2012-02-20","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"1213","Ordinal":"3","NoteData":"2017-11-17","Type":"Other","Title":"Modified"}]}}}