First published: Mon Feb 20 2012(Updated: )
Cross-site scripting (XSS) vulnerability in zimbra/h/calendar in Zimbra Web Client in Zimbra Collaboration Suite (ZCS) 6.x before 6.0.15 and 7.x before 7.1.3 allows remote attackers to inject arbitrary web script or HTML via the view parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zimbra |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1213 is classified as a medium severity cross-site scripting vulnerability.
To fix CVE-2012-1213, upgrade to Zimbra Collaboration Suite version 6.0.15 or 7.1.3 or later.
CVE-2012-1213 allows remote attackers to inject arbitrary web scripts or HTML, potentially compromising user data.
CVE-2012-1213 affects Zimbra Collaboration Suite versions 6.x prior to 6.0.15 and 7.x prior to 7.1.3.
CVE-2012-1213 is specifically related to cross-site scripting and does not share a direct relationship with other vulnerabilities.