CVE-2023-45207: XSS
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. An attacker can send a PDF document through mail that contains malicious JavaScript. While previewing this file in webmail in the Chrome browser, the stored XSS payload is executed. (This has been mitigated by sanitising the JavaScript code present in a PDF document.)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45207?
CVE-2023-45207 is considered a high severity vulnerability due to its potential for executing stored cross-site scripting (XSS) in Zimbra Collaboration.
How do I fix CVE-2023-45207?
To address CVE-2023-45207, apply the latest security updates provided by Zimbra for affected versions.
Which versions of Zimbra Collaboration are affected by CVE-2023-45207?
CVE-2023-45207 affects Zimbra Collaboration versions 8.8.15, 9.0, and up to 10.0.5.
What type of vulnerability is CVE-2023-45207?
CVE-2023-45207 is a stored cross-site scripting (XSS) vulnerability that allows attackers to execute malicious scripts.
How can I mitigate the risks associated with CVE-2023-45207?
To mitigate risks from CVE-2023-45207, ensure users do not open untrusted PDF attachments and maintain software updates.