CVE-2022-41349: XSS
In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/compose accepts an attachUrl parameter that is vulnerable to Reflected XSS. This allows executing arbitrary JavaScript on the victim's machine.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-41349?
CVE-2022-41349 is a vulnerability found in Zimbra Collaboration Suite (ZCS) 8.8.15 that allows for Reflected XSS attacks.
What is the severity of CVE-2022-41349?
The severity of CVE-2022-41349 is medium with a CVSS score of 6.1.
How does CVE-2022-41349 work?
CVE-2022-41349 works by exploiting the vulnerability in the URL at /h/compose that accepts an attachUrl parameter, allowing for the execution of arbitrary JavaScript on the victim's machine.
Which version of Zimbra Collaboration Suite is affected?
Zimbra Collaboration Suite 8.8.15 is the affected version.
How can I fix CVE-2022-41349?
To fix CVE-2022-41349, users should update to a patched version of Zimbra Collaboration Suite, provided by Zimbra.