Description
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected products
- Zimbra / Collaboration10.0 – 10.0.18
- Zimbra / Collaboration10.1 – 10.1.13
References
- VENDOR_ADVISORYhttps://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
- MISChttps://wiki.zimbra.com/wiki/Security_Center
- MISChttps://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy
- MISChttps://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.13#Security_Fixes
- MISChttps://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.18#Security_Fixes
Updated 21m ago · 8 sources