Beveiligingsadvies

CVE-2024-45512

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-11-21 00:00:00
Laatst bijgewerkt 2024-11-21 18:11:28
Toegewezen door mitre
CVSS-score 6.1
Status PUBLISHED

Beschrijving

An issue was discovered in webmail in Zimbra Collaboration (ZCS) through 10.1. An attacker can exploit this vulnerability by creating a folder in the Briefcase module with a malicious payload and sharing it with a victim. When the victim interacts with the folder share notification, the malicious script executes in their browser. This stored Cross-Site Scripting (XSS) vulnerability can lead to unauthorized actions within the victim's session.