Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-87926
HistoryOct 14, 2022 - 12:00 a.m.

Zimbra Collaboration Suite phone cross-site scripting vulnerability

2022-10-1400:00:00
China National Vulnerability Database
www.cnvd.org.cn
9
synacor zcs
collaboration suite
cross-site scripting
phone parameter
voicemail action
javascript vulnerability

0.001 Low

EPSS

Percentile

33.7%

Synacor Zimbra Collaboration Suite (ZCS) is an open source collaboration suite from Synacor, Inc. A cross-site scripting vulnerability exists in Zimbra Collaboration Suite version 8.8.15, which stems from the lack of effective filtering and escaping of user-supplied data in the phone parameter of /h/search?action=voicemail & action=listen, which could be exploited to execute arbitrary JavaScript.

0.001 Low

EPSS

Percentile

33.7%

Related for CNVD-2022-87926