CVE-2019-12427: XSS
Zimbra Collaboration before 8.8.15 Patch 1 is vulnerable to a non-persistent XSS via the Admin Console.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-12427?
CVE-2019-12427 is a vulnerability in Zimbra Collaboration before 8.8.15 Patch 1 that allows non-persistent XSS via the Admin Console.
How severe is CVE-2019-12427?
CVE-2019-12427 has a severity level of medium with a score of 4.8.
Which software versions are affected by CVE-2019-12427?
Zimbra Collaboration Server versions up to and including 8.8.15 are affected by CVE-2019-12427.
How can I fix CVE-2019-12427?
To fix CVE-2019-12427, update Zimbra Collaboration to version 8.8.15 Patch 1 or later.
Where can I find more information about CVE-2019-12427?
More information about CVE-2019-12427 can be found at the following references: - [Bugzilla](https://bugzilla.zimbra.com/show_bug.cgi?id=109174) - [Zimbra Security Center](https://wiki.zimbra.com/wiki/Security_Center) - [Zimbra Security Advisories](https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories)