Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-87927
HistoryOct 14, 2022 - 12:00 a.m.

Zimbra Collaboration Suite uncheck cross-site scripting vulnerability

2022-10-1400:00:00
China National Vulnerability Database
www.cnvd.org.cn
11
zimbra collaboration suite
synacor
cross-site scripting
vulnerability
filtering
escaping
user-supplied data
javascript code
cnvd

0.001 Low

EPSS

Percentile

33.7%

Synacor Zimbra Collaboration Suite (ZCS) is an open source collaboration suite from Synacor, Inc. A cross-site scripting vulnerability exists in Zimbra Collaboration Suite version 8.8.15, which stems from the lack of effective filtering and escaping of user-supplied data in the uncheck parameter in /h/calendar, which could be exploited to inject JavaScript code.

0.001 Low

EPSS

Percentile

33.7%

Related for CNVD-2022-87927