CVE-2025-27914
- EPSS 0.27%
- Veröffentlicht 12.03.2025 00:00:00
- Zuletzt bearbeitet 02.04.2025 20:38:06
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Reflected Cross-Site Scripting (XSS) vulnerability exists in the /h/rest endpoint, allowing authenticated attackers to inject and execute arbitrary JavaScript in a victim'...
CVE-2025-25065
- EPSS 0.58%
- Veröffentlicht 03.02.2025 20:15:37
- Zuletzt bearbeitet 11.06.2025 21:18:20
SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4 allows unauthorized redirection to internal network endpoints.
CVE-2025-25064
- EPSS 36.73%
- Veröffentlicht 03.02.2025 20:15:37
- Zuletzt bearbeitet 11.06.2025 21:18:03
SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 due to insufficient sanitization of a user-supplied parameter. Authenticated attackers can exploit this vulnera...
CVE-2024-54663
- EPSS 0.6%
- Veröffentlicht 19.12.2024 23:15:07
- Zuletzt bearbeitet 11.06.2025 21:17:48
An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerability exists in the /h/rest endpoint, allowing authenticated remote attackers to include and access sensitive ...
CVE-2024-45513
- EPSS 0.39%
- Veröffentlicht 21.11.2024 17:15:15
- Zuletzt bearbeitet 11.06.2025 21:17:25
An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A stored Cross-Site Scripting (XSS) vulnerability exists in the /modern/contacts/print endpoint of Zimbra webmail. This allows an attacker to inject and execute arbitrary JavaScript ...
CVE-2024-45194
- EPSS 0.47%
- Veröffentlicht 21.11.2024 17:15:15
- Zuletzt bearbeitet 11.06.2025 15:40:45
In Zimbra Collaboration (ZCS) 9.0 and 10.0, a vulnerability in the Webmail Modern UI allows execution of stored Cross-Site Scripting (XSS) payloads. An attacker with administrative access to the Zimbra Administration Panel can inject malicious JavaSc...
CVE-2024-45517
- EPSS 0.53%
- Veröffentlicht 21.11.2024 17:15:15
- Zuletzt bearbeitet 11.06.2025 21:17:35
An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability in the /h/rest endpoint of the Zimbra webmail and admin panel interfaces allows attackers to execute arbitrary JavaScript in the victim's s...
CVE-2024-45514
- EPSS 0.65%
- Veröffentlicht 21.11.2024 16:15:25
- Zuletzt bearbeitet 11.06.2025 21:17:14
An issue was discovered in Zimbra Collaboration (ZCS) through v10.1. A Cross-Site Scripting (XSS) vulnerability exists in one of the endpoints of Zimbra Webmail due to insufficient sanitization of the packages parameter. Attackers can bypass the exis...
CVE-2024-45512
- EPSS 0.39%
- Veröffentlicht 21.11.2024 16:15:25
- Zuletzt bearbeitet 11.06.2025 21:17:07
An issue was discovered in webmail in Zimbra Collaboration (ZCS) through 10.1. An attacker can exploit this vulnerability by creating a folder in the Briefcase module with a malicious payload and sharing it with a victim. When the victim interacts wi...
CVE-2024-45510
- EPSS 0.31%
- Veröffentlicht 20.11.2024 20:15:18
- Zuletzt bearbeitet 11.06.2025 19:13:10
An issue was discovered in Zimbra Collaboration (ZCS) through 10.0. Zimbra Webmail (Modern UI) is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper sanitization of user input. This allows an attacker to inject malicious code in...