PT-2024-5816 · Zimbra · Zimbra Collaboration
Published
2024-08-12
·
Updated
2024-08-19
·
CVE-2024-33533
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Zimbra Collaboration (ZCS) versions 9.0 through 10.0
Description
A reflected cross-site scripting (XSS) vulnerability has been identified in the Zimbra webmail admin interface. This vulnerability occurs due to inadequate input validation of the
packages parameter, allowing an authenticated attacker to inject and execute arbitrary JavaScript code within the context of another user's browser session. By uploading a malicious JavaScript file and crafting a URL containing its location in the packages parameter, the attacker can exploit this vulnerability. Subsequently, when another user visits the crafted URL, the malicious JavaScript code is executed.Recommendations
For Zimbra Collaboration (ZCS) versions 9.0 through 10.0, consider disabling the vulnerable
packages parameter in the webmail admin interface as a temporary workaround until a patch is available. Restrict access to the webmail admin interface to minimize the risk of exploitation. Avoid using the packages parameter in the affected API endpoint until the issue is resolved. Update to version 10.0.8 or later, as it includes security fixes for the identified vulnerabilities.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zimbra Collaboration