CVE-2020-13653
02.07.2020, 16:15
An XSS vulnerability exists in the Webmail component of Zimbra Collaboration Suite before 8.8.15 Patch 11. It allows an attacker to inject executable JavaScript into the account name of a user's profile. The injected code can be reflected and executed when changing an e-mail signature.
Vendor | Product | Version |
---|---|---|
synacor | zimbra_collaboration_suite | 𝑥 < 8.8.15 |
synacor | zimbra_collaboration_suite | 8.8.15 |
synacor | zimbra_collaboration_suite | 8.8.15:p1 |
synacor | zimbra_collaboration_suite | 8.8.15:p10 |
synacor | zimbra_collaboration_suite | 8.8.15:p2 |
synacor | zimbra_collaboration_suite | 8.8.15:p3 |
synacor | zimbra_collaboration_suite | 8.8.15:p4 |
synacor | zimbra_collaboration_suite | 8.8.15:p5 |
synacor | zimbra_collaboration_suite | 8.8.15:p6 |
synacor | zimbra_collaboration_suite | 8.8.15:p7 |
synacor | zimbra_collaboration_suite | 8.8.15:p8 |
synacor | zimbra_collaboration_suite | 8.8.15:p9 |
𝑥
= Vulnerable software versions
References