Cross-Site Scripting Flaw in Zimbra Collaboration Suite
CVE-2013-1938

6.1MEDIUM

Key Information:

Vendor

Zimbra

Status
Vendor
CVE Published:
12 February 2020

What is CVE-2013-1938?

Zimbra Collaboration Suite 2013 has a Cross-Site Scripting (XSS) vulnerability in the 'aspell.php' file, allowing attackers to inject malicious scripts into web pages viewed by users. Successfully exploiting this flaw can lead to unauthorized access to sensitive information or manipulation of the user's session, posing significant risks to users' data integrity and security.

Affected Version(s)

Zimbra 2013

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.