QID 379282
Date Published: 2024-01-31
QID 379282: Zimbra Cross-Site Scripting (XSS) Vulnerability
Zimbra is a complete email, address book, calendar and tasks solution that can be accessed from the Zimbra Web Client, Zimbra Desktop offline client, Outlook and a variety of other standards-based email clients and mobile devices.
An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.4. An XSS issue can be exploited to access the mailbox of an authenticated user. This is also fixed in 8.8.15 Patch 43 and 9.0.0 Patch 36.
Affected Software:
Synacor Zimbra Collaboration Suite 8.8.x before 8.8.15 Patch 43
Synacor Zimbra Collaboration Suite 9.0.x before 9.0.0 Patch 36
Synacor Zimbra Collaboration Suite 10.0.x before 10.0.4
QID Detection Logic:
This QID runs "zmcontrol -v" to check the vulnerable version
Successful exploitation of this issue allows an attacker to compromise confidentiality and integrity
- Zimbra Security Advisories -
wiki.zimbra.com/wiki/Zimbra_Security_Advisories
CVEs related to QID 379282
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Zimbra |
|