Podatność CVE-2023-43102


Publikacja: 2023-12-07   Modyfikacja: 2023-12-14

Opis:
An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.4. An XSS issue can be exploited to access the mailbox of an authenticated user. This is also fixed in 8.8.15 Patch 43 and 9.0.0 Patch 36.

Typ:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

Affected software
Zimbra -> Collaboration 

 Referencje:
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
https://wiki.zimbra.com/wiki/Security_Center

Copyright 2024, cxsecurity.com

 

Back to Top