Zimbra Collaboration before Kepler 9.0.0 Patch 38 GA allows DOM-based JavaScript injection in the Modern UI.
History

Mon, 19 Aug 2024 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-02-13T00:00:00

Updated: 2024-08-19T14:45:34.594Z

Reserved: 2023-12-14T00:00:00

Link: CVE-2023-50808

cve-icon Vulnrichment

Updated: 2024-08-02T22:23:43.056Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-02-13T18:15:47.320

Modified: 2024-08-19T15:35:01.787

Link: CVE-2023-50808

cve-icon Redhat

No data.