Show filters
68 Total Results
Displaying 21-30 of 68
Sort by:
Attacker Value
Unknown

CVE-2023-45206

Disclosure Date: February 13, 2024 (last updated October 08, 2024)
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. Through the help document endpoint in webmail, an attacker can inject JavaScript or HTML code that leads to cross-site scripting (XSS). (Adding an adequate message to avoid malicious code will mitigate this issue.)
Attacker Value
Unknown

CVE-2023-26562

Disclosure Date: February 13, 2024 (last updated October 22, 2024)
In Zimbra Collaboration (ZCS) 8.8.15 and 9.0, a closed account (with 2FA and generated passwords) can send e-mail messages when configured for Imap/smtp.
Attacker Value
Unknown

CVE-2017-20188

Disclosure Date: January 02, 2024 (last updated January 10, 2024)
A vulnerability has been found in Zimbra zm-ajax up to 8.8.1 and classified as problematic. Affected by this vulnerability is the function XFormItem.prototype.setError of the file WebRoot/js/ajax/dwt/xforms/XFormItem.js. The manipulation of the argument message leads to cross site scripting. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 8.8.2 is able to address this issue. The identifier of the patch is 8d039d6efe80780adc40c6f670c06d21de272105. It is recommended to upgrade the affected component. The identifier VDB-249421 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-43103

Disclosure Date: December 07, 2023 (last updated December 13, 2023)
An XSS issue was discovered in a web endpoint in Zimbra Collaboration (ZCS) before 10.0.4 via an unsanitized parameter. This is also fixed in 8.8.15 Patch 43 and 9.0.0 Patch 36.
Attacker Value
Unknown

CVE-2023-43102

Disclosure Date: December 07, 2023 (last updated December 13, 2023)
An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.4. An XSS issue can be exploited to access the mailbox of an authenticated user. This is also fixed in 8.8.15 Patch 43 and 9.0.0 Patch 36.
Attacker Value
Unknown

CVE-2023-41106

Disclosure Date: December 07, 2023 (last updated December 13, 2023)
An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.3. An attacker can gain access to a Zimbra account. This is also fixed in 9.0.0 Patch 35 and 8.8.15 Patch 42.
Attacker Value
Unknown

CVE-2023-38750

Disclosure Date: July 31, 2023 (last updated October 08, 2023)
In Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41, 9 before 9.0.0 Patch 34, and 10 before 10.0.2, internal JSP and XML files can be exposed.
Attacker Value
Unknown

CVE-2023-34193

Disclosure Date: July 06, 2023 (last updated October 08, 2023)
File Upload vulnerability in Zimbra ZCS 8.8.15 allows an authenticated privileged user to execute arbitrary code and obtain sensitive information via the ClientUploader function.
Attacker Value
Unknown

CVE-2023-34192

Disclosure Date: July 06, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.
Attacker Value
Unknown

CVE-2023-29381

Disclosure Date: July 06, 2023 (last updated October 08, 2023)
An issue in Zimbra Collaboration (ZCS) v.8.8.15 and v.9.0 allows a remote attacker to escalate privileges and obtain sensitive information via the password and 2FA parameters.