PT-2024-13227 · Zimbra · Zimbra Collaboration

Published

2024-02-13

·

Updated

2024-10-07

·

CVE-2023-45206

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Zimbra Collaboration (ZCS) versions 8.8.15 through 10.0
Description An issue was discovered in Zimbra Collaboration, where an attacker can inject JavaScript or HTML code through the help document endpoint in webmail, leading to cross-site scripting (XSS). Adding an adequate message to avoid malicious code can mitigate this issue.
Recommendations For Zimbra Collaboration (ZCS) versions 8.8.15 through 10.0, consider adding an adequate message to avoid malicious code as a mitigation measure until a patch is available. As a temporary workaround, restrict access to the help document endpoint in webmail to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-45206

Affected Products

Zimbra Collaboration