CVE-2023-37580: Zimbra Collaboration (ZCS) Cross-Site Scripting (XSS) Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability impacting the confidentiality and integrity of data.
Other sources
Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Synacor Zimbra Collaboration Suite (ZCS) - Zimbra Classic Web Clientto a version that resolves this vulnerability.Fixed in 8.8.15Patch Patch 41
Event History
Frequently Asked Questions
What is CVE-2023-37580?
CVE-2023-37580 is a cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (ZCS) that impacts the confidentiality and integrity of data.
Which Zimbra Collaboration versions are affected by CVE-2023-37580?
CVE-2023-37580 affects Zimbra Collaboration versions 8.8.15-p3 to 8.8.15-p40.
How severe is CVE-2023-37580?
CVE-2023-37580 has a severity rating of 6.1 (medium).
How can I fix CVE-2023-37580?
To fix CVE-2023-37580, it is recommended to upgrade Zimbra Collaboration to a patched version provided by Zimbra.
Where can I find more information about CVE-2023-37580?
You can find more information about CVE-2023-37580 on the Zimbra Security Center and Zimbra Responsible Disclosure Policy pages.