CVE-2019-8946: XSS
Published Jan 27, 2020
·Updated
Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS.
Affected Software
3 affected components
Zimbra Collaboration Server>=8.7.0<=8.8.11
Zimbra Collaboration Server=8.8.11-p1
Zimbra Collaboration Server=8.8.11-p2
Event History
Jan 27, 2020
CVE Published
via MITRE·06:36 PM
Data Sourced
via MITRE·06:36 PM
Description
Frequently Asked Questions
1
What is CVE-2019-8946?
CVE-2019-8946 is a vulnerability in Zimbra Collaboration 8.7.x - 8.8.11P2 that allows for persistent cross-site scripting (XSS) attacks.
2
How severe is CVE-2019-8946?
CVE-2019-8946 has a severity keyword of 'medium' with a severity value of 6.1 (out of 10).
3
How does CVE-2019-8946 affect Zimbra Collaboration Server?
CVE-2019-8946 affects Zimbra Collaboration Server versions 8.7.x to 8.8.11P2.
4
What is persistent XSS?
Persistent cross-site scripting (XSS) is a type of XSS attack where the injected code is permanently stored on the target server, allowing it to affect multiple users.
5
Is there a fix available for CVE-2019-8946?
Yes, Zimbra has released patches to fix the vulnerability. It is recommended to update to the latest version of Zimbra Collaboration Server.