Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-87924
HistoryOct 14, 2022 - 12:00 a.m.

Zimbra Collaboration Suite attachUrl parameter cross-site scripting vulnerability

2022-10-1400:00:00
China National Vulnerability Database
www.cnvd.org.cn
8
synacor
inc. webmail calendar address book cross-site scripting vulnerability attackers javascript arbitrary_cnvd

0.001 Low

EPSS

Percentile

33.5%

Synacor Zimbra Collaboration Suite (ZCS) is an open source collaboration suite from Synacor, Inc. The product includes WebMail, Calendar, Address Book, etc. A cross-site scripting vulnerability exists in Zimbra Collaboration Suite version 8.8.15, which stems from the lack of effective filtering and escaping of user-supplied data in the attachUrl parameter of /h/compose, which can be exploited by attackers to execute arbitrary JavaScript.

0.001 Low

EPSS

Percentile

33.5%

Related for CNVD-2022-87924