CVE-2023-24031
15.06.2023, 21:15
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 8.8.15. XSS can occur, via one of attributes of the webmail /h/ endpoint, to execute arbitrary JavaScript code, leading to information disclosure.
Vendor | Product | Version |
---|---|---|
zimbra | collaboration | 9.0.0 |
zimbra | collaboration | 9.0.0:p0 |
zimbra | collaboration | 9.0.0:p1 |
zimbra | collaboration | 9.0.0:p10 |
zimbra | collaboration | 9.0.0:p11 |
zimbra | collaboration | 9.0.0:p12 |
zimbra | collaboration | 9.0.0:p13 |
zimbra | collaboration | 9.0.0:p14 |
zimbra | collaboration | 9.0.0:p15 |
zimbra | collaboration | 9.0.0:p19 |
zimbra | collaboration | 9.0.0:p2 |
zimbra | collaboration | 9.0.0:p23 |
zimbra | collaboration | 9.0.0:p25 |
zimbra | collaboration | 9.0.0:p26 |
zimbra | collaboration | 9.0.0:p27 |
zimbra | collaboration | 9.0.0:p3 |
zimbra | collaboration | 9.0.0:p4 |
zimbra | collaboration | 9.0.0:p5 |
zimbra | collaboration | 9.0.0:p6 |
zimbra | collaboration | 9.0.0:p7 |
zimbra | collaboration | 9.0.0:p7.1 |
zimbra | collaboration | 9.0.0:p8 |
zimbra | collaboration | 9.0.0:p9 |
𝑥
= Vulnerable software versions