Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xvvw-m6mf-m9hw

Опубликовано: 13 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. XSS, with resultant session stealing, can occur via JavaScript code in a link (for a webmail redirection endpoint) within en email message, e.g., if a victim clicks on that link within Zimbra webmail.

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. XSS, with resultant session stealing, can occur via JavaScript code in a link (for a webmail redirection endpoint) within en email message, e.g., if a victim clicks on that link within Zimbra webmail.

EPSS

Процентиль: 68%
0.00569
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 1 года назад

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. XSS, with resultant session stealing, can occur via JavaScript code in a link (for a webmail redirection endpoint) within en email message, e.g., if a victim clicks on that link within Zimbra webmail.

EPSS

Процентиль: 68%
0.00569
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79