QID 379332
Date Published: 2024-02-02
QID 379332: Zimbra Collaboration Suite (ZCS) Extensible Markup Language (XML) Exposure Vulnerability
Zimbra is a complete email, address book, calendar and tasks solution that can be accessed from the Zimbra Web Client, Zimbra Desktop offline client, Outlook and a variety of other standards-based email clients and mobile devices.
In Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41, 9 before 9.0.0 Patch 34, and 10 before 10.0.2, internal JSP and XML files can be exposed.
Affected Software:
Synacor Zimbra Collaboration Suite 8.8.x before 8.8.15 Patch 41
Synacor Zimbra Collaboration Suite 9.0.x before 9.0.0 Patch 34
Synacor Zimbra Collaboration Suite 10.0.x before 10.0.2
QID Detection Logic:
This QID runs "zmcontrol -v" to check the vulnerable version
Successful exploitation of this issue allows an attacker to compromise confidentiality and integrity
- Zimbra Security Advisories -
wiki.zimbra.com/wiki/Zimbra_Security_Advisories
CVEs related to QID 379332
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Zimbra |
|