Zimbra.Warning.Dialog.XSS

description-logoDescription

This indicates an attack attempt against a Cross-Site Scripting (XSS) vulnerability in Zimbra Collaboration.
The vulnerability is caused due to insufficient sanitizing of warning dialog content. It allows remote attackers to launch XSS attack against Zimbra Collaboration users.

affected-products-logoAffected Products

Zimbra Collaboration 8.6.0 Patch4 and earlier

Impact logoImpact

System Compromise: Remote attackers can execute arbitrary script code in the context of the affected user.

recomended-action-logoRecommended Actions

Apply latest patch from the vendors.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)