CVE-2020-13653: XSS
An XSS vulnerability exists in the Webmail component of Zimbra Collaboration Suite before 8.8.15 Patch 11. It allows an attacker to inject executable JavaScript into the account name of a user's profile. The injected code can be reflected and executed when changing an e-mail signature.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-13653?
CVE-2020-13653 is an XSS vulnerability that exists in the Webmail component of Zimbra Collaboration Suite before version 8.8.15 Patch 11.
How does CVE-2020-13653 work?
The vulnerability allows an attacker to inject executable JavaScript into the account name of a user's profile, which can be reflected and executed when changing an email signature.
What is the severity of CVE-2020-13653?
The severity of CVE-2020-13653 is medium, with a CVSS score of 6.1.
Which versions of Zimbra Collaboration Suite are affected by CVE-2020-13653?
Zimbra Collaboration Suite versions before 8.8.15 Patch 11 are affected by CVE-2020-13653.
How can I fix CVE-2020-13653?
To fix CVE-2020-13653, update Zimbra Collaboration Suite to version 8.8.15 Patch 11 or later.