CVE-2024-45515: XSS
An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability exists in Zimbra webmail due to insufficient validation of the content type metadata when importing files into the briefcase. Attackers can exploit this issue by crafting a file with manipulated metadata, allowing them to bypass content type checks and execute arbitrary JavaScript within the victim's session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45515?
CVE-2024-45515 is classified as a critical severity vulnerability due to its potential for exploitation through Cross-Site Scripting.
How do I fix CVE-2024-45515?
To fix CVE-2024-45515, upgrade your Zimbra Collaboration software to version 10.1 or later with the latest security patches installed.
What kind of vulnerability is CVE-2024-45515?
CVE-2024-45515 is a Cross-Site Scripting (XSS) vulnerability found in Zimbra webmail.
Which versions of Zimbra Collaboration are affected by CVE-2024-45515?
CVE-2024-45515 affects all versions of Zimbra Collaboration Suite up to and including version 10.1.
How can attackers exploit CVE-2024-45515?
Attackers can exploit CVE-2024-45515 by importing specially crafted files into the Zimbra briefcase that bypass content type validations.