CVE-2021-35207: XSS
An issue was discovered in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.0 before 9.0.0 Patch 16. An XSS vulnerability exists in the login component of Zimbra Web Client, in which an attacker can execute arbitrary JavaScript by adding executable JavaScript to the loginErrorCode parameter of the login url.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-35207?
The severity of CVE-2021-35207 is medium.
What is the affected software for CVE-2021-35207?
The affected software for CVE-2021-35207 is Zimbra Collaboration Suite versions 8.8 before 8.8.15 Patch 23 and 9.0 before 9.0.0 Patch 16.
How can an attacker exploit CVE-2021-35207?
An attacker can exploit CVE-2021-35207 by adding executable JavaScript to the loginErrorCode parameter in the login component of Zimbra Web Client.
How can CVE-2021-35207 be fixed?
CVE-2021-35207 can be fixed by upgrading to Zimbra Collaboration Suite versions 8.8.15 Patch 23 or later, and 9.0.0 Patch 16 or later.
Where can I find more information about CVE-2021-35207?
You can find more information about CVE-2021-35207 on the Zimbra Collaboration Suite Security Center wiki page and the Zimbra Releases wiki pages.