First published: Fri Jan 06 2023(Updated: )
An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur on the Classic UI login page by injecting arbitrary JavaScript code in the username field. This occurs before the user logs into the system, which means that even if the attacker executes arbitrary JavaScript, they will not get any sensitive information.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zimbra Collaboration | =9.0.0 | |
Zimbra Collaboration | =9.0.0-p0 | |
Zimbra Collaboration | =9.0.0-p1 | |
Zimbra Collaboration | =9.0.0-p10 | |
Zimbra Collaboration | =9.0.0-p11 | |
Zimbra Collaboration | =9.0.0-p12 | |
Zimbra Collaboration | =9.0.0-p13 | |
Zimbra Collaboration | =9.0.0-p14 | |
Zimbra Collaboration | =9.0.0-p15 | |
Zimbra Collaboration | =9.0.0-p16 | |
Zimbra Collaboration | =9.0.0-p19 | |
Zimbra Collaboration | =9.0.0-p2 | |
Zimbra Collaboration | =9.0.0-p20 | |
Zimbra Collaboration | =9.0.0-p21 | |
Zimbra Collaboration | =9.0.0-p23 | |
Zimbra Collaboration | =9.0.0-p24 | |
Zimbra Collaboration | =9.0.0-p24.1 | |
Zimbra Collaboration | =9.0.0-p25 | |
Zimbra Collaboration | =9.0.0-p26 | |
Zimbra Collaboration | =9.0.0-p27 | |
Zimbra Collaboration | =9.0.0-p3 | |
Zimbra Collaboration | =9.0.0-p4 | |
Zimbra Collaboration | =9.0.0-p5 | |
Zimbra Collaboration | =9.0.0-p6 | |
Zimbra Collaboration | =9.0.0-p7 | |
Zimbra Collaboration | =9.0.0-p7.1 | |
Zimbra Collaboration | =9.0.0-p8 | |
Zimbra Collaboration | =9.0.0-p9 | |
=9.0.0 | ||
=9.0.0-p0 | ||
=9.0.0-p1 | ||
=9.0.0-p10 | ||
=9.0.0-p11 | ||
=9.0.0-p12 | ||
=9.0.0-p13 | ||
=9.0.0-p14 | ||
=9.0.0-p15 | ||
=9.0.0-p16 | ||
=9.0.0-p19 | ||
=9.0.0-p2 | ||
=9.0.0-p20 | ||
=9.0.0-p21 | ||
=9.0.0-p23 | ||
=9.0.0-p24 | ||
=9.0.0-p24.1 | ||
=9.0.0-p25 | ||
=9.0.0-p26 | ||
=9.0.0-p27 | ||
=9.0.0-p3 | ||
=9.0.0-p4 | ||
=9.0.0-p5 | ||
=9.0.0-p6 | ||
=9.0.0-p7 | ||
=9.0.0-p7.1 | ||
=9.0.0-p8 | ||
=9.0.0-p9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-45911 is medium, with a CVSS score of 6.1.
An attacker can exploit CVE-2022-45911 by injecting arbitrary JavaScript code in the username field of the Classic UI login page in Zimbra Collaboration.
CVE-2022-45911 affects Zimbra Collaboration 9.0.0 and its patch versions from p0 to p27.
No, user authentication is not required for an attacker to exploit CVE-2022-45911 as the vulnerability occurs before the user logs into the system.
To fix CVE-2022-45911, it is recommended to upgrade Zimbra Collaboration to a patched version provided by the vendor.