CVE-2023-45206: XSS
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. Through the help document endpoint in webmail, an attacker can inject JavaScript or HTML code that leads to cross-site scripting (XSS). (Adding an adequate message to avoid malicious code will mitigate this issue.)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45206?
CVE-2023-45206 is classified as a medium severity vulnerability due to the possibility of cross-site scripting (XSS) attacks.
How do I fix CVE-2023-45206?
To fix CVE-2023-45206, ensure that message validation is implemented to avoid the injection of malicious JavaScript or HTML code.
Which versions of Zimbra are affected by CVE-2023-45206?
CVE-2023-45206 affects Zimbra Collaboration versions 8.8.15, 9.0, and all 10.0 versions up to 10.0.5.
Can CVE-2023-45206 lead to data theft?
Yes, successful exploitation of CVE-2023-45206 can potentially lead to data theft through XSS, allowing attackers to steal session cookies or other sensitive data.
Is there a known exploit for CVE-2023-45206?
As of now, specific public exploits for CVE-2023-45206 have not been reported, but the vulnerability's nature poses a risk if left unpatched.