PT-2022-25820 · Zimbra · Zimbra Collaboration

Published

2022-10-12

·

Updated

2022-10-13

·

CVE-2022-41348

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Zimbra Collaboration (ZCS) version 9.0
Description An issue in Zimbra Collaboration allows XSS to occur via the onerror attribute of an IMG element. This can lead to information disclosure.
Recommendations For Zimbra Collaboration (ZCS) version 9.0, update to a version that includes a fix for this issue to prevent information disclosure through XSS attacks.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-41348

Affected Products

Zimbra Collaboration