Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-45511

Опубликовано: 20 нояб. 2024
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A reflected Cross-Site Scripting (XSS) issue exists through the Briefcase module due to improper sanitization of file content by the OnlyOffice formatter. This occurs when the victim opens a crafted URL pointing to a shared folder containing a malicious file uploaded by the attacker. The vulnerability allows the attacker to execute arbitrary JavaScript in the context of the victim's session.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:*
Версия до 10.0.9 (исключая)
cpe:2.3:a:synacor:zimbra_collaboration_suite:10.1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 41%
0.00193
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
github
около 1 года назад

An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A reflected Cross-Site Scripting (XSS) issue exists through the Briefcase module due to improper sanitization of file content by the OnlyOffice formatter. This occurs when the victim opens a crafted URL pointing to a shared folder containing a malicious file uploaded by the attacker. The vulnerability allows the attacker to execute arbitrary JavaScript in the context of the victim's session.

CVSS3: 8.3
fstec
около 1 года назад

Уязвимость модуля Briefcase корпоративной системы управления электронной почтой Zimbra Collaboration Suite (ZCS), позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

EPSS

Процентиль: 41%
0.00193
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79