CVE-2022-41348
- EPSS 0.66%
- Veröffentlicht 12.10.2022 20:15:11
- Zuletzt bearbeitet 15.05.2025 15:16:03
An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur via the onerror attribute of an IMG element, leading to information disclosure.
CVE-2022-41349
- EPSS 0.57%
- Veröffentlicht 12.10.2022 20:15:11
- Zuletzt bearbeitet 15.05.2025 15:16:03
In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/compose accepts an attachUrl parameter that is vulnerable to Reflected XSS. This allows executing arbitrary JavaScript on the victim's machine.
CVE-2022-41350
- EPSS 0.66%
- Veröffentlicht 12.10.2022 20:15:11
- Zuletzt bearbeitet 15.05.2025 15:16:04
In Zimbra Collaboration Suite (ZCS) 8.8.15, /h/search?action=voicemail&action=listen accepts a phone parameter that is vulnerable to Reflected XSS. This allows executing arbitrary JavaScript on the victim's machine.
CVE-2022-41347
- EPSS 0.16%
- Veröffentlicht 26.09.2022 02:15:10
- Zuletzt bearbeitet 21.05.2025 19:16:04
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.x and 9.x (e.g., 8.8.15). The Sudo configuration permits the zimbra user to execute the NGINX binary as root with arbitrary parameters. As part of its intended functionality, NGINX can load a ...
CVE-2022-37393
- EPSS 5.12%
- Veröffentlicht 16.08.2022 20:15:07
- Zuletzt bearbeitet 21.11.2024 07:14:54
Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so ...
CVE-2022-37044
- EPSS 0.74%
- Veröffentlicht 12.08.2022 15:15:16
- Zuletzt bearbeitet 21.11.2024 07:14:20
In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/search?action accepts parameters called extra, title, and onload that are partially sanitised and lead to reflected XSS that allows executing arbitrary JavaScript on the victim's machine.
CVE-2022-37043
- EPSS 0.26%
- Veröffentlicht 12.08.2022 15:15:16
- Zuletzt bearbeitet 21.11.2024 07:14:20
An issue was discovered in the webmail component in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. When using preauth, CSRF tokens are not checked on some POST endpoints. Thus, when an authenticated user views an attacker-controlled page, a request...
CVE-2022-37041
- EPSS 0.23%
- Veröffentlicht 12.08.2022 15:15:16
- Zuletzt bearbeitet 21.11.2024 07:14:20
An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. The value of the X-Forwarded-Host header overwrites the value of the Host header in proxied requests. The value of X-Forwarded-Host...
CVE-2022-32294
- EPSS 2.17%
- Veröffentlicht 11.07.2022 03:15:07
- Zuletzt bearbeitet 21.11.2024 07:06:07
Zimbra Collaboration Open Source 8.8.15 does not encrypt the initial-login randomly created password (from the "zmprove ca" command). It is visible in cleartext on port UDP 514 (aka the syslog port). NOTE: a third party reports that this cannot be re...
CVE-2021-35209
- EPSS 2.45%
- Veröffentlicht 02.07.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:12:03
An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.x before 9.0.0 Patch 16. The value of the X-Host header overwrites the value of the Host header in proxied requests. The...