Lucene search

K
cvelistMitreCVELIST:CVE-2022-41350
HistoryOct 12, 2022 - 12:00 a.m.

CVE-2022-41350

2022-10-1200:00:00
mitre
www.cve.org
zimbra
collaboration suite
xss
vulnerability
javascript

6.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

33.7%

In Zimbra Collaboration Suite (ZCS) 8.8.15, /h/search?action=voicemail&action=listen accepts a phone parameter that is vulnerable to Reflected XSS. This allows executing arbitrary JavaScript on the victim’s machine.

6.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

33.7%

Related for CVELIST:CVE-2022-41350