CVE-2019-7219: XSS
Unauthenticated reflected cross-site scripting (XSS) exists in Zarafa Webapp 2.0.1.47791 and earlier. NOTE: this is a discontinued product. The issue was fixed in later Zarafa Webapp versions; however, some former Zarafa Webapp customers use the related Kopano product instead.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7219?
CVE-2019-7219 has a medium severity due to the potential for exploitation via reflected cross-site scripting.
How do I fix CVE-2019-7219?
To fix CVE-2019-7219, upgrade to a version of Zarafa Webapp that is later than 2.0.1.47791.
What impact does CVE-2019-7219 have?
CVE-2019-7219 allows attackers to execute arbitrary scripts in the context of a user's browser session.
Who is affected by CVE-2019-7219?
Users of Zarafa Webapp versions 2.0.1.47791 and earlier are affected by CVE-2019-7219.
Is Zarafa Webapp still supported for CVE-2019-7219?
Zarafa Webapp is a discontinued product, which means it is no longer officially supported, including for CVE-2019-7219.