PT-2024-13227 · Zimbra · Zimbra Collaboration

CVE-2023-45206

·

Published

2024-02-13

·

Updated

2024-10-07

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Zimbra Collaboration (ZCS) versions 8.8.15 through 10.0
Description An issue was discovered in Zimbra Collaboration, where an attacker can inject JavaScript or HTML code through the help document endpoint in webmail, leading to cross-site scripting (XSS). Adding an adequate message to avoid malicious code can mitigate this issue.
Recommendations For Zimbra Collaboration (ZCS) versions 8.8.15 through 10.0, consider adding an adequate message to avoid malicious code as a mitigation measure until a patch is available. As a temporary workaround, restrict access to the help document endpoint in webmail to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-45206

Affected Products

Zimbra Collaboration