CVE-2024-27443 - Zimbra Collaboration ZCS Cross-Site Scripting Vulnerability

CVE ID : CVE-2024-27443 Published : Aug. 12, 2024, 3:15 p.m. | 2 hours, 14 minutes ago Description : An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Aug 12, 2024 - 19:30
 0  2
CVE-2024-27443 - Zimbra Collaboration ZCS Cross-Site Scripting Vulnerability
CVE ID : CVE-2024-27443
Published : Aug. 12, 2024, 3:15 p.m. | 2 hours, 14 minutes ago
Description : An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...