Zimbra

Collaboration

57 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 36.22%
  • Veröffentlicht 03.02.2025 20:15:37
  • Zuletzt bearbeitet 11.06.2025 21:18:03

SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 due to insufficient sanitization of a user-supplied parameter. Authenticated attackers can exploit this vulnera...

  • EPSS 0.17%
  • Veröffentlicht 19.12.2024 23:15:07
  • Zuletzt bearbeitet 11.06.2025 21:17:48

An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerability exists in the /h/rest endpoint, allowing authenticated remote attackers to include and access sensitive ...

  • EPSS 0.1%
  • Veröffentlicht 21.11.2024 17:15:15
  • Zuletzt bearbeitet 11.06.2025 21:17:25

An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A stored Cross-Site Scripting (XSS) vulnerability exists in the /modern/contacts/print endpoint of Zimbra webmail. This allows an attacker to inject and execute arbitrary JavaScript ...

  • EPSS 0.08%
  • Veröffentlicht 21.11.2024 17:15:15
  • Zuletzt bearbeitet 11.06.2025 15:40:45

In Zimbra Collaboration (ZCS) 9.0 and 10.0, a vulnerability in the Webmail Modern UI allows execution of stored Cross-Site Scripting (XSS) payloads. An attacker with administrative access to the Zimbra Administration Panel can inject malicious JavaSc...

  • EPSS 0.16%
  • Veröffentlicht 21.11.2024 17:15:15
  • Zuletzt bearbeitet 11.06.2025 21:17:35

An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability in the /h/rest endpoint of the Zimbra webmail and admin panel interfaces allows attackers to execute arbitrary JavaScript in the victim's s...

  • EPSS 0.11%
  • Veröffentlicht 21.11.2024 16:15:25
  • Zuletzt bearbeitet 11.06.2025 21:17:14

An issue was discovered in Zimbra Collaboration (ZCS) through v10.1. A Cross-Site Scripting (XSS) vulnerability exists in one of the endpoints of Zimbra Webmail due to insufficient sanitization of the packages parameter. Attackers can bypass the exis...

  • EPSS 0.15%
  • Veröffentlicht 21.11.2024 16:15:25
  • Zuletzt bearbeitet 11.06.2025 21:17:07

An issue was discovered in webmail in Zimbra Collaboration (ZCS) through 10.1. An attacker can exploit this vulnerability by creating a folder in the Briefcase module with a malicious payload and sharing it with a victim. When the victim interacts wi...

  • EPSS 0.32%
  • Veröffentlicht 20.11.2024 20:15:18
  • Zuletzt bearbeitet 11.06.2025 19:13:10

An issue was discovered in Zimbra Collaboration (ZCS) through 10.0. Zimbra Webmail (Modern UI) is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper sanitization of user input. This allows an attacker to inject malicious code in...

  • EPSS 0.2%
  • Veröffentlicht 20.11.2024 19:15:06
  • Zuletzt bearbeitet 11.06.2025 21:16:54

An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A reflected Cross-Site Scripting (XSS) issue exists through the Briefcase module due to improper sanitization of file content by the OnlyOffice formatter. This occurs when the victim...

  • EPSS 20.52%
  • Veröffentlicht 22.10.2024 17:15:03
  • Zuletzt bearbeitet 30.10.2024 21:23:59

An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41, and 8.8.15 before Patch 46. It allows authenticated users to exploit Server-Side Request Forgery (SSRF) due to improper input san...