Логотип exploitDog
bind:CVE-2020-11737
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-11737

Количество 2

Количество 2

nvd логотип

CVE-2020-11737

почти 6 лет назад

A cross-site scripting (XSS) vulnerability in Web Client in Zimbra 9.0 allows a remote attacker to craft links in an E-Mail message or calendar invite to execute arbitrary JavaScript. The attack requires an A element containing an href attribute with a "www" substring (including the quotes) followed immediately by a DOM event listener such as onmouseover. This is fixed in 9.0.0 Patch 2.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-v5c5-9fh5-f3wx

больше 4 лет назад

Cross-site scripting in Zimbra

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-11737

A cross-site scripting (XSS) vulnerability in Web Client in Zimbra 9.0 allows a remote attacker to craft links in an E-Mail message or calendar invite to execute arbitrary JavaScript. The attack requires an A element containing an href attribute with a "www" substring (including the quotes) followed immediately by a DOM event listener such as onmouseover. This is fixed in 9.0.0 Patch 2.

CVSS3: 6.1
2%
Низкий
почти 6 лет назад
github логотип
GHSA-v5c5-9fh5-f3wx

Cross-site scripting in Zimbra

CVSS3: 6.1
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу