Zimbra Collaboration Cross-Site Scripting (CVE-2023-37580)

Related Vulnerabilities: CVE-2023-37580  

Check Point Reference: CPAI-2023-1183 Date Published: 19 Nov 2023 Severity: Medium Last Updated: Sunday 19 November, 2023 Source: Industry Reference:CVE-2023-37580
Protection Provided by:

Security Gateway
R81, R80, R77, R75

Who is Vulnerable? Zimbra Collaboration from 8.8.80 up to 8.8.15
Zimbra Collaboration 8.8.15 p11
Zimbra Collaboration 8.8.15 p26
Zimbra Collaboration 8.8.15 p3
Zimbra Collaboration 8.8.15 p30
Zimbra Collaboration 8.8.15 p31
Zimbra Collaboration 8.8.15 p32
Zimbra Collaboration 8.8.15 p33
Zimbra Collaboration 8.8.15 p34
Zimbra Collaboration 8.8.15 p35
Zimbra Collaboration 8.8.15 p37
Zimbra Collaboration 8.8.15 p38
Zimbra Collaboration 8.8.15 p40
Zimbra Collaboration 8.8.15 p5 Vulnerability Description A cross-site scripting vulnerability exists in Zimbra Collaboration. Successful exploitation of this vulnerability would allow remote attackers to inject arbitrary web script into the affected system.