Non-persistent XSS Vulnerability in Zimbra Collaboration Admin Console
CVE-2019-12427
4.8MEDIUM
What is CVE-2019-12427?
Zimbra Collaboration versions prior to 8.8.15 Patch 1 are exposed to a non-persistent Cross-Site Scripting (XSS) vulnerability that can be exploited via the Admin Console. Attackers may leverage this flaw to inject malicious scripts into pages viewed by administrators, potentially leading to unauthorized actions or data exposure. This highlights the critical need for users to keep their Zimbra installations updated to mitigate the risk posed by this type of vulnerability.