First published: Fri Jan 20 2012(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Desktop 7.1.2 b10978 allow remote attackers to inject arbitrary web script or HTML via the (1) Username or (2) MailBox Name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Vmware Zimbra Desktop | =7.1.2-b10978 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0903 is classified as a moderate severity vulnerability due to its potential to allow cross-site scripting attacks.
To fix CVE-2012-0903, upgrade Zimbra Desktop to a version later than 7.1.2 b10978 that addresses these XSS vulnerabilities.
Exploiting CVE-2012-0903 could allow attackers to execute arbitrary scripts in the context of the user's session, potentially compromising sensitive data.
CVE-2012-0903 affects Zimbra Desktop version 7.1.2 b10978 and earlier versions.
Users of Zimbra Desktop version 7.1.2 b10978 are at risk from CVE-2012-0903 due to the possibility of cross-site scripting attacks.