CVE-2024-45514
A Cross-Site Scripting (XSS) vulnerability exists in one of the endpoints of Zimbra Webmail due to insufficient sanitization of the packages parameter.
Does this matter?
Lower severity and a low EPSS score (0.63%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Zimbra Collaboration (ZCS) through v10.1. A Cross-Site Scripting (XSS) vulnerability exists in one of the endpoints of Zimbra Webmail due to insufficient sanitization of the packages parameter. Attackers can bypass the existing checks by using encoded characters, allowing the injection and execution of arbitrary JavaScript within a victim's session.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.63% probability · 48th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- synacor/zimbra collaboration suite
- Source
- cve@mitre.org
References
- https://wiki.zimbra.com/wiki/Security_CenterVendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.9#Security_FixesRelease Notes
- https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.1#Security_FixesRelease Notes
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P46#Security_FixesRelease Notes
- https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P41#Security_FixesRelease Notes
- https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_PolicyProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.