Home
HIGH: 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:NDefault status
unaffected
10.0 (custom) before 10.0.18
affected
10.1 (custom) before 10.1.13
affected
Description
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
10.0 (custom) before 10.0.18
10.1 (custom) before 10.1.13
References
wiki.zimbra.com/wiki/Zimbra_Security_Advisories
wiki.zimbra.com/wiki/Security_Center
wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy
wiki.zimbra.com/wiki/Zimbra_Releases/10.1.13
wiki.zimbra.com/wiki/Zimbra_Releases/10.0.18