CVE-2022-41348: XSS
Published Oct 12, 2022
·Updated
An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur via the onerror attribute of an IMG element, leading to information disclosure.
Affected Software
1 affected component
Zimbra Collaboration=9.0.0
Event History
Oct 12, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-41348?
The severity of CVE-2022-41348 is medium with a value of 6.1.
2
How can XSS occur in Zimbra Collaboration 9.0 (CVE-2022-41348)?
XSS can occur via the onerror attribute of an IMG element in Zimbra Collaboration 9.0.
3
What is the impact of the XSS vulnerability in Zimbra Collaboration 9.0 (CVE-2022-41348)?
The XSS vulnerability in Zimbra Collaboration 9.0 allows for information disclosure.
4
How can I fix the XSS vulnerability in Zimbra Collaboration 9.0 (CVE-2022-41348)?
To fix the XSS vulnerability in Zimbra Collaboration 9.0, apply the appropriate patches or upgrades provided by Zimbra.
5
Where can I find more information about the vulnerability (CVE-2022-41348)?
You can find more information about the CVE-2022-41348 vulnerability on the Zimbra Security Center and Zimbra Security Advisories.