CVE-2024-45513: XSS
An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A stored Cross-Site Scripting (XSS) vulnerability exists in the /modern/contacts/print endpoint of Zimbra webmail. This allows an attacker to inject and execute arbitrary JavaScript code in the context of the victim's browser when a crafted vCard (VCF) file is processed and printed. This could lead to unauthorized actions within the victim's session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45513?
CVE-2024-45513 is a stored Cross-Site Scripting (XSS) vulnerability rated as high severity.
How do I fix CVE-2024-45513?
To fix CVE-2024-45513, upgrade Zimbra Collaboration (ZCS) to version 10.1.1 or later.
What software is affected by CVE-2024-45513?
CVE-2024-45513 affects Zimbra Collaboration (ZCS) versions up to and including 10.1.
What types of attacks can CVE-2024-45513 facilitate?
CVE-2024-45513 can facilitate arbitrary JavaScript code execution in a victim's browser, potentially leading to session hijacking or data theft.
Is user action required to exploit CVE-2024-45513?
Yes, user action is required to exploit CVE-2024-45513 as an attacker must trick the user into accessing the malicious endpoint.