First published: Wed Nov 20 2024(Updated: )
An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A reflected Cross-Site Scripting (XSS) issue exists through the Briefcase module due to improper sanitization of file content by the OnlyOffice formatter. This occurs when the victim opens a crafted URL pointing to a shared folder containing a malicious file uploaded by the attacker. The vulnerability allows the attacker to execute arbitrary JavaScript in the context of the victim's session.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zimbra Collaboration Suite | <10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-45511 is classified as a reflected Cross-Site Scripting (XSS) vulnerability, which can lead to unauthorized actions on behalf of the user.
To mitigate CVE-2024-45511, upgrade to the latest version of Zimbra Collaboration that addresses this vulnerability.
CVE-2024-45511 affects Zimbra Collaboration (ZCS) versions up to 10.1.
CVE-2024-45511 is a reflected Cross-Site Scripting (XSS) vulnerability due to improper sanitization of file content.
Yes, CVE-2024-45511 can be exploited remotely when a user opens a crafted URL pointing to a shared folder.