PT-2024-13228 · Google+1 · Google Chrome+1
Ramin
·
Published
2024-01-18
·
Updated
2024-10-07
·
CVE-2023-45207
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Zimbra Collaboration (ZCS) versions 8.8.15 through 10.0
Description
An issue was discovered in Zimbra Collaboration, where an attacker can send a malicious PDF document through mail that contains JavaScript code. When this file is previewed in webmail using the Chrome browser, the stored XSS payload is executed. The issue has been mitigated by sanitizing the JavaScript code present in a PDF document.
Recommendations
For Zimbra Collaboration (ZCS) versions 8.8.15 through 10.0, the issue has been mitigated by sanitising the JavaScript code present in a PDF document. As a temporary workaround, consider disabling the preview of PDF documents in webmail until the issue is fully resolved. Restrict access to the webmail feature to minimize the risk of exploitation. Avoid using the webmail preview feature for PDF documents until the issue is resolved.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Google Chrome
Zimbra Collaboration