跳转到帖子

A Cross-Site Scripting (XSS) vulnerability caused by a non-sanitized `packages` parameter has been resolved.

recommended_posts

发布于
  • Members

A Cross-Site Scripting (XSS) vulnerability caused by a non-sanitized `packages` parameter has been resolved.

Severity
5
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:N)
Published
11/21/2024
Created
01/16/2025
Added
01/10/2025
Modified
01/20/2025

Description

An issue was discovered in Zimbra Collaboration (ZCS) through v10.1. A Cross-Site Scripting (XSS) vulnerability exists in one of the endpoints of Zimbra Webmail due to insufficient sanitization of the packages parameter. Attackers can bypass the existing checks by using encoded characters, allowing the injection and execution of arbitrary JavaScript within a victim's session.

Solution(s)

  • zimbra-collaboration-upgrade-latest

References

  • https://attackerkb.com/topics/cve-2024-45514
  • CVE - 2024-45514
  • https://wiki.zimbra.com/wiki/Security_Center
  • https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy
  • https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.1#Security_Fixes
  • https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.9#Security_Fixes
  • https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P41#Security_Fixes
  • https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P46#Security_Fixes
View more
  • 查看数 701
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…