6.1

CVE-2024-50599

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, affecting one of the webmail calendar endpoints. This arises from improper handling of user-supplied input, allowing an attacker to inject malicious code that is reflected back in the HTML response.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SynacorZimbra Collaboration Suite Version8.8.15 Update-
SynacorZimbra Collaboration Suite Version8.8.15 Updatep1
SynacorZimbra Collaboration Suite Version8.8.15 Updatep10
SynacorZimbra Collaboration Suite Version8.8.15 Updatep11
SynacorZimbra Collaboration Suite Version8.8.15 Updatep12
SynacorZimbra Collaboration Suite Version8.8.15 Updatep13
SynacorZimbra Collaboration Suite Version8.8.15 Updatep14
SynacorZimbra Collaboration Suite Version8.8.15 Updatep15
SynacorZimbra Collaboration Suite Version8.8.15 Updatep16
SynacorZimbra Collaboration Suite Version8.8.15 Updatep17
SynacorZimbra Collaboration Suite Version8.8.15 Updatep18
SynacorZimbra Collaboration Suite Version8.8.15 Updatep19
SynacorZimbra Collaboration Suite Version8.8.15 Updatep2
SynacorZimbra Collaboration Suite Version8.8.15 Updatep20
SynacorZimbra Collaboration Suite Version8.8.15 Updatep21
SynacorZimbra Collaboration Suite Version8.8.15 Updatep22
SynacorZimbra Collaboration Suite Version8.8.15 Updatep23
SynacorZimbra Collaboration Suite Version8.8.15 Updatep24
SynacorZimbra Collaboration Suite Version8.8.15 Updatep25
SynacorZimbra Collaboration Suite Version8.8.15 Updatep26
SynacorZimbra Collaboration Suite Version8.8.15 Updatep27
SynacorZimbra Collaboration Suite Version8.8.15 Updatep28
SynacorZimbra Collaboration Suite Version8.8.15 Updatep29
SynacorZimbra Collaboration Suite Version8.8.15 Updatep3
SynacorZimbra Collaboration Suite Version8.8.15 Updatep30
SynacorZimbra Collaboration Suite Version8.8.15 Updatep31
SynacorZimbra Collaboration Suite Version8.8.15 Updatep31.1
SynacorZimbra Collaboration Suite Version8.8.15 Updatep32
SynacorZimbra Collaboration Suite Version8.8.15 Updatep33
SynacorZimbra Collaboration Suite Version8.8.15 Updatep34
SynacorZimbra Collaboration Suite Version8.8.15 Updatep35
SynacorZimbra Collaboration Suite Version8.8.15 Updatep36
SynacorZimbra Collaboration Suite Version8.8.15 Updatep37
SynacorZimbra Collaboration Suite Version8.8.15 Updatep38
SynacorZimbra Collaboration Suite Version8.8.15 Updatep39
SynacorZimbra Collaboration Suite Version8.8.15 Updatep4
SynacorZimbra Collaboration Suite Version8.8.15 Updatep40
SynacorZimbra Collaboration Suite Version8.8.15 Updatep41
SynacorZimbra Collaboration Suite Version8.8.15 Updatep42
SynacorZimbra Collaboration Suite Version8.8.15 Updatep43
SynacorZimbra Collaboration Suite Version8.8.15 Updatep44
SynacorZimbra Collaboration Suite Version8.8.15 Updatep45
SynacorZimbra Collaboration Suite Version8.8.15 Updatep5
SynacorZimbra Collaboration Suite Version8.8.15 Updatep6
SynacorZimbra Collaboration Suite Version8.8.15 Updatep7
SynacorZimbra Collaboration Suite Version8.8.15 Updatep8
SynacorZimbra Collaboration Suite Version8.8.15 Updatep9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.47% 0.636
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.