CVE-2023-43102: XSS
An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.4. An XSS issue can be exploited to access the mailbox of an authenticated user. This is also fixed in 8.8.15 Patch 43 and 9.0.0 Patch 36.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-43102?
CVE-2023-43102 is classified as a high severity vulnerability due to its potential for XSS attacks that can access user mailboxes.
How do I fix CVE-2023-43102?
To fix CVE-2023-43102, upgrade Zimbra Collaboration to version 10.0.4 or apply patches provided in versions 8.8.15 Patch 43 and 9.0.0 Patch 36.
What types of systems are affected by CVE-2023-43102?
CVE-2023-43102 affects Zimbra Collaboration versions prior to 10.0.4 and specific patch levels of versions 8.8.15 and 9.0.0.
Can CVE-2023-43102 be remotely exploited?
Yes, CVE-2023-43102 can be exploited remotely due to its XSS nature, allowing attackers to access an authenticated user's mailbox.
Is there a workaround for CVE-2023-43102?
There are no known workarounds for CVE-2023-43102; patching to a secure version is the recommended solution.