PT-2024-10389 · Zimbra · Zimbra Collaboration Suite
Published
2024-09-01
·
Updated
2025-06-11
·
CVE-2024-45512
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Zimbra Collaboration Suite (ZCS) versions through 10.1
Description
The issue exists due to inadequate protection of the web page structure in the Briefcase Module of the Zimbra Collaboration Suite (ZCS). An attacker can exploit this by creating a folder in the Briefcase module with a malicious payload and sharing it with a victim. When the victim interacts with the folder share notification, the malicious script executes in their browser, leading to unauthorized actions within the victim's session. This is a stored Cross-Site Scripting (XSS) vulnerability.
Recommendations
For Zimbra Collaboration Suite (ZCS) versions through 10.1, update to Zimbra Daffodil (v10.1.1) or later to fix the Stored Cross-Site Scripting (XSS) vulnerability in the Briefcase module.
As a temporary workaround, consider restricting access to the Briefcase module until a patch is applied.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zimbra Collaboration Suite