PT-2024-31676 · Zimbra · Zimbra Collaboration
Published
2024-09-23
·
Updated
2024-11-21
·
CVE-2024-45517
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Zimbra Collaboration (ZCS) versions through 10.1
Description:
A Cross-Site Scripting (XSS) issue in the "/h/rest" endpoint of the Zimbra webmail and admin panel interfaces allows attackers to execute arbitrary JavaScript in the victim's session. This is caused by improper sanitization of user input, potentially compromising sensitive information. Exploitation requires user interaction to access the malicious URL.
Recommendations:
For versions through 10.1, update to Zimbra Daffodil (v10.1.1) or later to fix the Cross-Site Scripting (XSS) vulnerability in the "/h/rest" endpoint.
As a temporary workaround, consider restricting access to the "/h/rest" endpoint until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zimbra Collaboration