6.1

CVE-2021-35207

An issue was discovered in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.0 before 9.0.0 Patch 16. An XSS vulnerability exists in the login component of Zimbra Web Client, in which an attacker can execute arbitrary JavaScript by adding executable JavaScript to the loginErrorCode parameter of the login url.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZimbraCollaboration Version >= 8.8 < 8.8.15
ZimbraCollaboration Version8.8.15 Update-
ZimbraCollaboration Version8.8.15 Updatep1
ZimbraCollaboration Version8.8.15 Updatep10
ZimbraCollaboration Version8.8.15 Updatep11
ZimbraCollaboration Version8.8.15 Updatep12
ZimbraCollaboration Version8.8.15 Updatep13
ZimbraCollaboration Version8.8.15 Updatep14
ZimbraCollaboration Version8.8.15 Updatep15
ZimbraCollaboration Version8.8.15 Updatep16
ZimbraCollaboration Version8.8.15 Updatep17
ZimbraCollaboration Version8.8.15 Updatep18
ZimbraCollaboration Version8.8.15 Updatep19
ZimbraCollaboration Version8.8.15 Updatep2
ZimbraCollaboration Version8.8.15 Updatep20
ZimbraCollaboration Version8.8.15 Updatep21
ZimbraCollaboration Version8.8.15 Updatep22
ZimbraCollaboration Version8.8.15 Updatep3
ZimbraCollaboration Version8.8.15 Updatep4
ZimbraCollaboration Version8.8.15 Updatep5
ZimbraCollaboration Version8.8.15 Updatep6
ZimbraCollaboration Version8.8.15 Updatep7
ZimbraCollaboration Version8.8.15 Updatep8
ZimbraCollaboration Version8.8.15 Updatep9
ZimbraCollaboration Version9.0.0 Update-
ZimbraCollaboration Version9.0.0 Updatep1
ZimbraCollaboration Version9.0.0 Updatep10
ZimbraCollaboration Version9.0.0 Updatep11
ZimbraCollaboration Version9.0.0 Updatep12
ZimbraCollaboration Version9.0.0 Updatep13
ZimbraCollaboration Version9.0.0 Updatep14
ZimbraCollaboration Version9.0.0 Updatep15
ZimbraCollaboration Version9.0.0 Updatep2
ZimbraCollaboration Version9.0.0 Updatep3
ZimbraCollaboration Version9.0.0 Updatep4
ZimbraCollaboration Version9.0.0 Updatep5
ZimbraCollaboration Version9.0.0 Updatep6
ZimbraCollaboration Version9.0.0 Updatep7
ZimbraCollaboration Version9.0.0 Updatep8
ZimbraCollaboration Version9.0.0 Updatep9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.06% 0.77
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.