Synacor

Zimbra Collaboration Suite

74 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 23.06.2025 00:00:00
  • Zuletzt bearbeitet 11.07.2025 14:32:05

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potentially leadin...

  • EPSS 0.12%
  • Veröffentlicht 14.05.2025 00:00:00
  • Zuletzt bearbeitet 11.06.2025 21:20:29

An issue was discovered in Zimbra Collaboration (ZCS) 9.0.0 before Patch 43, 10.0.x before 10.0.12, 10.1.x before 10.1.4, and 8.8.15 before Patch 47. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbi...

  • EPSS 0.02%
  • Veröffentlicht 29.04.2025 00:00:00
  • Zuletzt bearbeitet 11.06.2025 21:20:21

In Zimbra Collaboration (ZCS) 9.0 through 10.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the GraphQL endpoint (/service/extension/graphql) of Zimbra webmail due to a lack of CSRF token validation. This allows attackers to perform u...

Warnung Exploit
  • EPSS 30.62%
  • Veröffentlicht 12.03.2025 00:00:00
  • Zuletzt bearbeitet 04.11.2025 16:45:11

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an e-mail...

  • EPSS 0.3%
  • Veröffentlicht 03.02.2025 20:15:37
  • Zuletzt bearbeitet 11.06.2025 21:18:20

SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4 allows unauthorized redirection to internal network endpoints.

  • EPSS 36.22%
  • Veröffentlicht 03.02.2025 20:15:37
  • Zuletzt bearbeitet 11.06.2025 21:18:03

SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 due to insufficient sanitization of a user-supplied parameter. Authenticated attackers can exploit this vulnera...

  • EPSS 0.1%
  • Veröffentlicht 19.12.2024 23:15:07
  • Zuletzt bearbeitet 11.06.2025 21:17:48

An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerability exists in the /h/rest endpoint, allowing authenticated remote attackers to include and access sensitive ...

  • EPSS 0.1%
  • Veröffentlicht 21.11.2024 17:15:15
  • Zuletzt bearbeitet 11.06.2025 21:17:25

An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A stored Cross-Site Scripting (XSS) vulnerability exists in the /modern/contacts/print endpoint of Zimbra webmail. This allows an attacker to inject and execute arbitrary JavaScript ...

  • EPSS 0.08%
  • Veröffentlicht 21.11.2024 17:15:15
  • Zuletzt bearbeitet 11.06.2025 15:40:45

In Zimbra Collaboration (ZCS) 9.0 and 10.0, a vulnerability in the Webmail Modern UI allows execution of stored Cross-Site Scripting (XSS) payloads. An attacker with administrative access to the Zimbra Administration Panel can inject malicious JavaSc...

  • EPSS 0.16%
  • Veröffentlicht 21.11.2024 17:15:15
  • Zuletzt bearbeitet 11.06.2025 21:17:35

An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability in the /h/rest endpoint of the Zimbra webmail and admin panel interfaces allows attackers to execute arbitrary JavaScript in the victim's s...