Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.
https://www.ic3.gov/Media/News/2024/241010.pdf
https://www.darkreading.com/cyberattacks-data-breaches/recent-zimbra-rce-under-attack-patch-now
https://thehackernews.com/2023/11/zero-day-flaw-in-zimbra-email-software.html
https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy
https://wiki.zimbra.com/wiki/Security_Center
http://www.openwall.com/lists/oss-security/2023/11/17/2
Source: Mitre, NVD
Published: 2023-07-31
Updated: 2025-02-25
Known Exploited Vulnerability (KEV)
Base Score: 6.4
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N
Severity: Medium
Base Score: 6.1
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS: 0.93864