An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.4. An XSS issue can be exploited to access the mailbox of an authenticated user. This is also fixed in 8.8.15 Patch 43 and 9.0.0 Patch 36.
                
            References
                    | Link | Resource | 
|---|---|
| https://wiki.zimbra.com/wiki/Security_Center | Patch | 
| https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    No history.
Information
                Published : 2023-12-07 06:15
Updated : 2023-12-12 17:11
NVD link : CVE-2023-43102
Mitre link : CVE-2023-43102
CVE.ORG link : CVE-2023-43102
JSON object : View
Products Affected
                zimbra
- collaboration
CWE
                
                    
                        
                        CWE-79
                        
            Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
