DOM-Based JavaScript Injection Vulnerability in Zimbra Collaboration Software
CVE-2023-50808

6.1MEDIUM

Key Information:

Vendor

Zimbra

Vendor
CVE Published:
13 February 2024

What is CVE-2023-50808?

A DOM-based JavaScript injection issue has been identified in Zimbra Collaboration prior to the Kepler 9.0.0 Patch 38 GA. This vulnerability allows attackers to execute malicious scripts within the context of the affected application. This can lead to unauthorized access to sensitive information or manipulation of site behavior, potentially compromising the security and integrity of user data.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-50808 : DOM-Based JavaScript Injection Vulnerability in Zimbra Collaboration Software