6.1
CVSSv3

CVE-2022-27926

Published: 21/04/2022 Updated: 08/08/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated malicious users to execute arbitrary web script or HTML via request parameters.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zimbra collaboration 9.0.0

Recent Articles

Pro-Russia cyber gang Winter Vivern puts US, Euro lawmakers in line of fire
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources Winter is coming for NATO countries

A cyber spy gang supporting Russia is targeting US elected officials and their staffers, in addition to European lawmakers, using unpatched Zimbra Collaboration software in two campaigns spotted by Proofpoint. The advanced persistent threat (APT) group – which Proofpoint tracks as TA473 and the Ukrainian CERT has named UAC-0114, while other private security researchers call it Winter Vivern – was first discovered by DomainTools' team and has been active since December 2020. At the time, the ...

Quick: Manually patch this Zimbra bug that's under attack
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources Smells like Russian cyber spies (again)

A vulnerability in Zimbra's software is being exploited right now by miscreants to compromise systems and attack selected government organizations, experts reckon. An update to squash the security bug won't be pushed out until later this month, according to the developer, which for now has "kindly" asked customers to manually apply a fix. The flaw affects Zimbra Collaboration Suite version 8.8.15, and "could potentially impact the confidentiality and integrity of your data," according to an advi...