CVE Tools

Zimbra urges customers to patch critical web client XSS flaw

BleepingComputerBy Sergiu Gatlan

PatchZimbra Collaboration Suite

Our summary

Zimbra has issued an urgent update for a critical cross-site scripting (XSS) vulnerability impacting the Classic Web Client of its widely used Zimbra Collaboration Suite. The flaw, which allows attackers to inject malicious scripts via specially crafted emails, remains unassigned a CVE ID but is now patched in version 10.1.19. While there is no evidence of active exploitation at this time, the vulnerability was reported by Google’s Threat Analysis Group, known for uncovering sophisticated cyber threats. Zimbra strongly advises all users of the Classic Web Client to upgrade immediately to prevent potential theft of session data and mailbox information.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store