CVE-2025-25064
- EPSS 36.22%
- Veröffentlicht 03.02.2025 20:15:37
- Zuletzt bearbeitet 11.06.2025 21:18:03
SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 due to insufficient sanitization of a user-supplied parameter. Authenticated attackers can exploit this vulnera...
CVE-2024-54663
- EPSS 0.17%
- Veröffentlicht 19.12.2024 23:15:07
- Zuletzt bearbeitet 11.06.2025 21:17:48
An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerability exists in the /h/rest endpoint, allowing authenticated remote attackers to include and access sensitive ...
CVE-2024-45513
- EPSS 0.1%
- Veröffentlicht 21.11.2024 17:15:15
- Zuletzt bearbeitet 11.06.2025 21:17:25
An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A stored Cross-Site Scripting (XSS) vulnerability exists in the /modern/contacts/print endpoint of Zimbra webmail. This allows an attacker to inject and execute arbitrary JavaScript ...
CVE-2024-45194
- EPSS 0.08%
- Veröffentlicht 21.11.2024 17:15:15
- Zuletzt bearbeitet 11.06.2025 15:40:45
In Zimbra Collaboration (ZCS) 9.0 and 10.0, a vulnerability in the Webmail Modern UI allows execution of stored Cross-Site Scripting (XSS) payloads. An attacker with administrative access to the Zimbra Administration Panel can inject malicious JavaSc...
CVE-2024-45517
- EPSS 0.16%
- Veröffentlicht 21.11.2024 17:15:15
- Zuletzt bearbeitet 11.06.2025 21:17:35
An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability in the /h/rest endpoint of the Zimbra webmail and admin panel interfaces allows attackers to execute arbitrary JavaScript in the victim's s...
CVE-2024-45514
- EPSS 0.11%
- Veröffentlicht 21.11.2024 16:15:25
- Zuletzt bearbeitet 11.06.2025 21:17:14
An issue was discovered in Zimbra Collaboration (ZCS) through v10.1. A Cross-Site Scripting (XSS) vulnerability exists in one of the endpoints of Zimbra Webmail due to insufficient sanitization of the packages parameter. Attackers can bypass the exis...
CVE-2024-45512
- EPSS 0.15%
- Veröffentlicht 21.11.2024 16:15:25
- Zuletzt bearbeitet 11.06.2025 21:17:07
An issue was discovered in webmail in Zimbra Collaboration (ZCS) through 10.1. An attacker can exploit this vulnerability by creating a folder in the Briefcase module with a malicious payload and sharing it with a victim. When the victim interacts wi...
CVE-2024-45510
- EPSS 0.32%
- Veröffentlicht 20.11.2024 20:15:18
- Zuletzt bearbeitet 11.06.2025 19:13:10
An issue was discovered in Zimbra Collaboration (ZCS) through 10.0. Zimbra Webmail (Modern UI) is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper sanitization of user input. This allows an attacker to inject malicious code in...
CVE-2024-45511
- EPSS 0.2%
- Veröffentlicht 20.11.2024 19:15:06
- Zuletzt bearbeitet 11.06.2025 21:16:54
An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A reflected Cross-Site Scripting (XSS) issue exists through the Briefcase module due to improper sanitization of file content by the OnlyOffice formatter. This occurs when the victim...
CVE-2024-45518
- EPSS 20.52%
- Veröffentlicht 22.10.2024 17:15:03
- Zuletzt bearbeitet 30.10.2024 21:23:59
An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41, and 8.8.15 before Patch 46. It allows authenticated users to exploit Server-Side Request Forgery (SSRF) due to improper input san...