PT-2026-26614 · Zimbra · Zimbra Collaboration
Publicado
2026-02-04
·
Atualizado
2026-03-22
·
CVE-2026-33370
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Zimbra Collaboration (ZCS) versions 10.0 and 10.1
Description
A stored cross-site scripting (XSS) issue exists in the Zimbra Briefcase feature because of inadequate sanitization of certain uploaded file types. When a user opens a publicly shared Briefcase file containing malicious scripts, the embedded JavaScript executes within the user’s session. This could allow an attacker to execute arbitrary scripts, potentially resulting in data exfiltration or other unauthorized actions performed as the victim user.
Recommendations
Update to a newer version that contains a fix for this vulnerability.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zimbra Collaboration