Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.openwall.com/lists/oss-security/2023/11/17/2 | Mailing List Patch | 
| https://wiki.zimbra.com/wiki/Security_Center | Release Notes | 
| https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy | Not Applicable | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    No history.
Information
                Published : 2023-07-31 16:15
Updated : 2023-12-22 15:16
NVD link : CVE-2023-37580
Mitre link : CVE-2023-37580
CVE.ORG link : CVE-2023-37580
JSON object : View
Products Affected
                zimbra
- zimbra
CWE
                
                    
                        
                        CWE-79
                        
            Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
