Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
PatchZimbra Email PlatformOur summary
Zimbra has issued security updates for its email platform to resolve several high-severity vulnerabilities, including a critical command injection flaw in the SNMP monitoring component. The latest patch, Zimbra 10.1.20, also resolves four cross-site scripting (XSS) issues in the Classic Web Client. These flaws could allow attackers to execute malicious scripts or bypass mail forwarding restrictions. While there is no evidence of active exploitation, past XSS vulnerabilities in Zimbra have been targeted by threat actors, underscoring the importance of applying this update promptly.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.