Lucene search

K
cvelistMitreCVELIST:CVE-2022-41349
HistoryOct 12, 2022 - 12:00 a.m.

CVE-2022-41349

2022-10-1200:00:00
mitre
www.cve.org
1
zimbra
collaboration suite
reflected xss

6.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

33.5%

In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/compose accepts an attachUrl parameter that is vulnerable to Reflected XSS. This allows executing arbitrary JavaScript on the victim’s machine.

6.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

33.5%

Related for CVELIST:CVE-2022-41349