Zimbra Web Client (ZWC) in Zimbra Collaboration Suite 8.8 before 8.8.8.Patch4 and 8.7 before 8.7.11.Patch4 has Persistent XSS via a contact group.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://wiki.zimbra.com/wiki/Security_Center | patch vendor advisory |
https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.8/P4 | patch vendor advisory release notes |
https://blog.zimbra.com/2018/05/new-zimbra-patches-8-8-8-patch-4-and-8-7-11-patch-4/ | patch vendor advisory |
https://wiki.zimbra.com/wiki/Zimbra_Releases/8.7.11/P4 | patch vendor advisory release notes |
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories | patch vendor advisory |