Description

An issue was discovered in webmail in Zimbra Collaboration (ZCS) through 10.1. An attacker can exploit this vulnerability by creating a folder in the Briefcase module with a malicious payload and sharing it with a victim. When the victim interacts with the folder share notification, the malicious script executes in their browser. This stored Cross-Site Scripting (XSS) vulnerability can lead to unauthorized actions within the victim's session.

INFO

Published Date :

2024-11-21T00:00:00.000Z

Last Modified :

2024-11-21T18:11:28.172Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2024-45512 vulnerability.

Vendors Products
Synacor
  • Zimbra Collaboration Suite

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact