CVE-2022-27926: Zimbra Collaboration (ZCS) Cross-Site Scripting (XSS) Vulnerability
A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated attackers to execute arbitrary web script or HTML via request parameters.
Other sources
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability by allowing an endpoint URL to accept parameters without sanitizing.
— CISA
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2022-27926?
CVE-2022-27926 is a reflected cross-site scripting (XSS) vulnerability in Zimbra Collaboration (ZCS) 9.0 that allows unauthenticated attackers to execute arbitrary web script or HTML via request parameters.
How can this vulnerability be exploited?
This vulnerability can be exploited by sending specially crafted request parameters to the /public/launchNewWindow.jsp component of Zimbra Collaboration (ZCS) 9.0.
Who is affected by CVE-2022-27926?
Users of Zimbra Collaboration (ZCS) 9.0 are affected by this vulnerability.
What is the severity of CVE-2022-27926?
CVE-2022-27926 has a severity rating of medium.
How can I mitigate CVE-2022-27926?
To mitigate this vulnerability, it is recommended to update Zimbra Collaboration to a patched version.