Synacor Zimbra Collaboration Suite (ZCS) is an open source collaboration suite from Synacor, Inc. The product includes WebMail, Calendar, Address Book, etc. A cross-site scripting vulnerability exists in Zimbra Collaboration Suite version 8.8.15, which stems from the lack of effective filtering and escaping of user-supplied data in the attachUrl parameter of /h/compose, which can be exploited by attackers to execute arbitrary JavaScript.
CPE | Name | Operator | Version |
---|---|---|---|
zimbra zimbra collaboration suite | eq | 8.8.15 |