First published: Thu Jul 06 2023(Updated: )
Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zimbra Collaboration Suite | =8.8.15 | |
Zimbra Collaboration Suite | =8.8.15-p1 | |
Zimbra Collaboration Suite | =8.8.15-p10 | |
Zimbra Collaboration Suite | =8.8.15-p11 | |
Zimbra Collaboration Suite | =8.8.15-p12 | |
Zimbra Collaboration Suite | =8.8.15-p13 | |
Zimbra Collaboration Suite | =8.8.15-p14 | |
Zimbra Collaboration Suite | =8.8.15-p15 | |
Zimbra Collaboration Suite | =8.8.15-p16 | |
Zimbra Collaboration Suite | =8.8.15-p17 | |
Zimbra Collaboration Suite | =8.8.15-p18 | |
Zimbra Collaboration Suite | =8.8.15-p19 | |
Zimbra Collaboration Suite | =8.8.15-p2 | |
Zimbra Collaboration Suite | =8.8.15-p20 | |
Zimbra Collaboration Suite | =8.8.15-p21 | |
Zimbra Collaboration Suite | =8.8.15-p22 | |
Zimbra Collaboration Suite | =8.8.15-p23 | |
Zimbra Collaboration Suite | =8.8.15-p24 | |
Zimbra Collaboration Suite | =8.8.15-p25 | |
Zimbra Collaboration Suite | =8.8.15-p26 | |
Zimbra Collaboration Suite | =8.8.15-p27 | |
Zimbra Collaboration Suite | =8.8.15-p28 | |
Zimbra Collaboration Suite | =8.8.15-p29 | |
Zimbra Collaboration Suite | =8.8.15-p3 | |
Zimbra Collaboration Suite | =8.8.15-p30 | |
Zimbra Collaboration Suite | =8.8.15-p31 | |
Zimbra Collaboration Suite | =8.8.15-p32 | |
Zimbra Collaboration Suite | =8.8.15-p33 | |
Zimbra Collaboration Suite | =8.8.15-p34 | |
Zimbra Collaboration Suite | =8.8.15-p35 | |
Zimbra Collaboration Suite | =8.8.15-p37 | |
Zimbra Collaboration Suite | =8.8.15-p4 | |
Zimbra Collaboration Suite | =8.8.15-p5 | |
Zimbra Collaboration Suite | =8.8.15-p6 | |
Zimbra Collaboration Suite | =8.8.15-p7 | |
Zimbra Collaboration Suite | =8.8.15-p8 | |
Zimbra Collaboration Suite | =8.8.15-p9 | |
Zimbra Collaboration Suite | ||
=8.8.15 | ||
=8.8.15-p1 | ||
=8.8.15-p10 | ||
=8.8.15-p11 | ||
=8.8.15-p12 | ||
=8.8.15-p13 | ||
=8.8.15-p14 | ||
=8.8.15-p15 | ||
=8.8.15-p16 | ||
=8.8.15-p17 | ||
=8.8.15-p18 | ||
=8.8.15-p19 | ||
=8.8.15-p2 | ||
=8.8.15-p20 | ||
=8.8.15-p21 | ||
=8.8.15-p22 | ||
=8.8.15-p23 | ||
=8.8.15-p24 | ||
=8.8.15-p25 | ||
=8.8.15-p26 | ||
=8.8.15-p27 | ||
=8.8.15-p28 | ||
=8.8.15-p29 | ||
=8.8.15-p3 | ||
=8.8.15-p30 | ||
=8.8.15-p31 | ||
=8.8.15-p32 | ||
=8.8.15-p33 | ||
=8.8.15-p34 | ||
=8.8.15-p35 | ||
=8.8.15-p37 | ||
=8.8.15-p4 | ||
=8.8.15-p5 | ||
=8.8.15-p6 | ||
=8.8.15-p7 | ||
=8.8.15-p8 | ||
=8.8.15-p9 |
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-34192 has a severity level of critical.
CVE-2023-34192 affects Zimbra Collaboration versions 8.8.15 and its subsequent patches.
CVE-2023-34192 allows a remote authenticated attacker to execute arbitrary code via a crafted script.
To fix CVE-2023-34192, apply the recommended patch from Zimbra Collaboration or upgrade to a patched version.
You can find more information about CVE-2023-34192 and Zimbra Collaboration security advisories on the Zimbra Security Center and Zimbra Wiki.