PT-2024-13228 · Google+1 · Google Chrome+1

Ramin

·

Published

2024-01-18

·

Updated

2024-10-07

·

CVE-2023-45207

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Zimbra Collaboration (ZCS) versions 8.8.15 through 10.0
Description An issue was discovered in Zimbra Collaboration, where an attacker can send a malicious PDF document through mail that contains JavaScript code. When this file is previewed in webmail using the Chrome browser, the stored XSS payload is executed. The issue has been mitigated by sanitizing the JavaScript code present in a PDF document.
Recommendations For Zimbra Collaboration (ZCS) versions 8.8.15 through 10.0, the issue has been mitigated by sanitising the JavaScript code present in a PDF document. As a temporary workaround, consider disabling the preview of PDF documents in webmail until the issue is fully resolved. Restrict access to the webmail feature to minimize the risk of exploitation. Avoid using the webmail preview feature for PDF documents until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-45207

Affected Products

Google Chrome
Zimbra Collaboration