PT-2026-26614 · Zimbra · Zimbra Collaboration

Publicado

2026-02-04

·

Atualizado

2026-03-22

·

CVE-2026-33370

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Zimbra Collaboration (ZCS) versions 10.0 and 10.1
Description A stored cross-site scripting (XSS) issue exists in the Zimbra Briefcase feature because of inadequate sanitization of certain uploaded file types. When a user opens a publicly shared Briefcase file containing malicious scripts, the embedded JavaScript executes within the user’s session. This could allow an attacker to execute arbitrary scripts, potentially resulting in data exfiltration or other unauthorized actions performed as the victim user.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-07902
CVE-2026-33370

Produtos afetados

Zimbra Collaboration