CVE-2021-35208: XSS
An issue was discovered in ZmMailMsgView.js in the Calendar Invite component in Zimbra Collaboration Suite 8.8.x before 8.8.15 Patch 23. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-35208?
CVE-2021-35208 is a vulnerability discovered in Zimbra Collaboration Suite 8.8.x before 8.8.15 Patch 23, which allows an attacker to inject arbitrary markup into emails.
How does CVE-2021-35208 affect Zimbra Collaboration Suite?
CVE-2021-35208 affects Zimbra Collaboration Suite versions 8.8.x before 8.8.15 Patch 23.
What is the severity of CVE-2021-35208?
The severity of CVE-2021-35208 is medium, with a CVSS score of 5.4.
How can I fix CVE-2021-35208?
To fix CVE-2021-35208, update Zimbra Collaboration Suite to version 8.8.15 Patch 23 or later.
Where can I find more information about CVE-2021-35208?
You can find more information about CVE-2021-35208 in the references provided: [link1], [link2], and [link3].