PT-2024-10600 · Zimbra · Zimbra

CVE-2017-20191

·

Published

2024-03-31

·

Updated

2024-05-17

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Zimbra versions up to 8.8.1
Description A problematic issue was found in the function XFormItem.prototype.setError of the file WebRoot/js/ajax/dwt/xforms/XFormItem.js of the component Form Textbox Field Error Handler. The manipulation of the argument message leads to cross-site scripting. It is possible to initiate the attack remotely.
Recommendations For Zimbra versions up to 8.8.1, upgrade to version 8.8.2 to address this issue. As a temporary workaround, consider restricting access to the XFormItem.prototype.setError function until the upgrade is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-20191

Affected Products

Zimbra