Zimbra

Zimbra Collaboration Suite

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.3%
  • Veröffentlicht 29.04.2025 00:00:00
  • Zuletzt bearbeitet 11.06.2025 21:20:21

In Zimbra Collaboration (ZCS) 9.0 through 10.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the GraphQL endpoint (/service/extension/graphql) of Zimbra webmail due to a lack of CSRF token validation. This allows attackers to perform u...

  • EPSS 0.6%
  • Veröffentlicht 19.12.2024 23:15:07
  • Zuletzt bearbeitet 11.06.2025 21:17:48

An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerability exists in the /h/rest endpoint, allowing authenticated remote attackers to include and access sensitive ...

  • EPSS 0.31%
  • Veröffentlicht 20.11.2024 19:15:06
  • Zuletzt bearbeitet 11.06.2025 21:16:54

An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A reflected Cross-Site Scripting (XSS) issue exists through the Briefcase module due to improper sanitization of file content by the OnlyOffice formatter. This occurs when the victim...

  • EPSS 60.65%
  • Veröffentlicht 07.11.2024 21:15:06
  • Zuletzt bearbeitet 17.06.2025 18:41:30

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, affecting one of the webmail calendar endpoints. This arises from improper handling of user-supplied input, allowing an attacker to i...

  • EPSS 1.23%
  • Veröffentlicht 30.05.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 02:37:03

Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x before 8.7.11 Patch 2, and 8.8.x before 8.8.8 Patch 1 allows remote attackers to hijack the authentication of unspe...

  • EPSS 1.45%
  • Veröffentlicht 30.05.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:21

Zimbra Web Client (ZWC) in Zimbra Collaboration Suite 8.8 before 8.8.8.Patch4 and 8.7 before 8.7.11.Patch4 has Persistent XSS via a contact group.