MEDIUM
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0
Published Feb 13, 2024
6.1
MEDIUMCVSS 3.1
EPSS 0.46%
Description
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. XSS, with resultant session stealing, can occur via JavaScript code in a link (for a webmail redirection endpoint) within en email message, e.g., if a victim clicks on that link within Zimbra webmail.
Affected products
No data.
OR
- ≥ 10.0.0 · < 10.0.6
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 8.8.15
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://wiki.zimbra.com/wiki/Security_Center Release Notes
- https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy Vendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://wiki.zimbra.com/wiki/Security_Center | Release Notes | |
| https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy | Vendor Advisory | |
| https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 13, 2024
Updated Mar 25, 2025
Reserved Nov 16, 2023
Link CVE-2023-48432
CISA Vulnrichment
Updated Feb 21, 2024