Lucene search

K
vulnrichmentMitreVULNRICHMENT:CVE-2023-48432
HistoryFeb 13, 2024 - 12:00 a.m.

CVE-2023-48432

2024-02-1300:00:00
mitre
github.com
2
zimbra collaboration
xss
session stealing
javascript
webmail redirection

AI Score

7

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. XSS, with resultant session stealing, can occur via JavaScript code in a link (for a webmail redirection endpoint) within en email message, e.g., if a victim clicks on that link within Zimbra webmail.

AI Score

7

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2023-48432