CVE-2024-45514

An issue was discovered in Zimbra Collaboration (ZCS) through v10.1. A Cross-Site Scripting (XSS) vulnerability exists in one of the endpoints of Zimbra Webmail due to insufficient sanitization of the packages parameter. Attackers can bypass the existing checks by using encoded characters, allowing the injection and execution of arbitrary JavaScript within a victim's session.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
mitreCNA
---
---
CISA-ADPADP
6.1 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 21%
VendorProductVersion
synacorzimbra_collaboration_suite
𝑥
< 8.8.15
synacorzimbra_collaboration_suite
10.0.0 ≤
𝑥
< 10.0.9
synacorzimbra_collaboration_suite
8.8.15
synacorzimbra_collaboration_suite
8.8.15:p1
synacorzimbra_collaboration_suite
8.8.15:p10
synacorzimbra_collaboration_suite
8.8.15:p11
synacorzimbra_collaboration_suite
8.8.15:p12
synacorzimbra_collaboration_suite
8.8.15:p13
synacorzimbra_collaboration_suite
8.8.15:p14
synacorzimbra_collaboration_suite
8.8.15:p15
synacorzimbra_collaboration_suite
8.8.15:p16
synacorzimbra_collaboration_suite
8.8.15:p17
synacorzimbra_collaboration_suite
8.8.15:p18
synacorzimbra_collaboration_suite
8.8.15:p19
synacorzimbra_collaboration_suite
8.8.15:p2
synacorzimbra_collaboration_suite
8.8.15:p20
synacorzimbra_collaboration_suite
8.8.15:p21
synacorzimbra_collaboration_suite
8.8.15:p22
synacorzimbra_collaboration_suite
8.8.15:p23
synacorzimbra_collaboration_suite
8.8.15:p24
synacorzimbra_collaboration_suite
8.8.15:p25
synacorzimbra_collaboration_suite
8.8.15:p26
synacorzimbra_collaboration_suite
8.8.15:p27
synacorzimbra_collaboration_suite
8.8.15:p28
synacorzimbra_collaboration_suite
8.8.15:p29
synacorzimbra_collaboration_suite
8.8.15:p3
synacorzimbra_collaboration_suite
8.8.15:p30
synacorzimbra_collaboration_suite
8.8.15:p31
synacorzimbra_collaboration_suite
8.8.15:p31.1
synacorzimbra_collaboration_suite
8.8.15:p32
synacorzimbra_collaboration_suite
8.8.15:p33
synacorzimbra_collaboration_suite
8.8.15:p34
synacorzimbra_collaboration_suite
8.8.15:p35
synacorzimbra_collaboration_suite
8.8.15:p36
synacorzimbra_collaboration_suite
8.8.15:p37
synacorzimbra_collaboration_suite
8.8.15:p38
synacorzimbra_collaboration_suite
8.8.15:p39
synacorzimbra_collaboration_suite
8.8.15:p4
synacorzimbra_collaboration_suite
8.8.15:p40
synacorzimbra_collaboration_suite
8.8.15:p41
synacorzimbra_collaboration_suite
8.8.15:p42
synacorzimbra_collaboration_suite
8.8.15:p43
synacorzimbra_collaboration_suite
8.8.15:p44
synacorzimbra_collaboration_suite
8.8.15:p45
synacorzimbra_collaboration_suite
8.8.15:p5
synacorzimbra_collaboration_suite
8.8.15:p6
synacorzimbra_collaboration_suite
8.8.15:p7
synacorzimbra_collaboration_suite
8.8.15:p8
synacorzimbra_collaboration_suite
8.8.15:p9
synacorzimbra_collaboration_suite
9.0.0
synacorzimbra_collaboration_suite
9.0.0:p1
synacorzimbra_collaboration_suite
9.0.0:p10
synacorzimbra_collaboration_suite
9.0.0:p11
synacorzimbra_collaboration_suite
9.0.0:p12
synacorzimbra_collaboration_suite
9.0.0:p13
synacorzimbra_collaboration_suite
9.0.0:p14
synacorzimbra_collaboration_suite
9.0.0:p15
synacorzimbra_collaboration_suite
9.0.0:p16
synacorzimbra_collaboration_suite
9.0.0:p17
synacorzimbra_collaboration_suite
9.0.0:p18
synacorzimbra_collaboration_suite
9.0.0:p19
synacorzimbra_collaboration_suite
9.0.0:p2
synacorzimbra_collaboration_suite
9.0.0:p20
synacorzimbra_collaboration_suite
9.0.0:p21
synacorzimbra_collaboration_suite
9.0.0:p22
synacorzimbra_collaboration_suite
9.0.0:p23
synacorzimbra_collaboration_suite
9.0.0:p24
synacorzimbra_collaboration_suite
9.0.0:p24.1
synacorzimbra_collaboration_suite
9.0.0:p25
synacorzimbra_collaboration_suite
9.0.0:p26
synacorzimbra_collaboration_suite
9.0.0:p27
synacorzimbra_collaboration_suite
9.0.0:p28
synacorzimbra_collaboration_suite
9.0.0:p29
synacorzimbra_collaboration_suite
9.0.0:p3
synacorzimbra_collaboration_suite
9.0.0:p30
synacorzimbra_collaboration_suite
9.0.0:p31
synacorzimbra_collaboration_suite
9.0.0:p32
synacorzimbra_collaboration_suite
9.0.0:p33
synacorzimbra_collaboration_suite
9.0.0:p34
synacorzimbra_collaboration_suite
9.0.0:p35
synacorzimbra_collaboration_suite
9.0.0:p36
synacorzimbra_collaboration_suite
9.0.0:p37
synacorzimbra_collaboration_suite
9.0.0:p38
synacorzimbra_collaboration_suite
9.0.0:p39
synacorzimbra_collaboration_suite
9.0.0:p4
synacorzimbra_collaboration_suite
9.0.0:p40
synacorzimbra_collaboration_suite
9.0.0:p5
synacorzimbra_collaboration_suite
9.0.0:p6
synacorzimbra_collaboration_suite
9.0.0:p7
synacorzimbra_collaboration_suite
9.0.0:p8
synacorzimbra_collaboration_suite
9.0.0:p9
synacorzimbra_collaboration_suite
10.1.0
𝑥
= Vulnerable software versions