Zimbra Collaboration before 8.8.10 GA allows text content spoofing via a loginErrorCode value.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Link | Tags |
---|---|
https://bugzilla.zimbra.com/show_bug.cgi?id=109021 | third party advisory permissions required |
https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.10 | release notes vendor advisory |