Cross-Site Scripting in Zimbra Collaboration by Zimbra
CVE-2023-24031
6.1MEDIUM
What is CVE-2023-24031?
A vulnerability has been identified in Zimbra Collaboration Suite (ZCS) versions 9.0 and 8.8.15, enabling attackers to exploit a Cross-Site Scripting (XSS) flaw via specific attributes in the webmail /h/ endpoint. This can result in the execution of arbitrary JavaScript code, potentially leading to unauthorized information disclosure, threatening user data integrity and privacy.