Cross-Site Scripting Vulnerability in Zimbra Collaboration by Zimbra
CVE-2024-45516
6.1MEDIUM
What is CVE-2024-45516?
A Cross-Site Scripting vulnerability in Zimbra Collaboration's Classic UI enables attackers to execute arbitrary JavaScript by leveraging insufficient sanitization of HTML content in emails. This vulnerability allows unauthorized access to sensitive information when a victim views a specially crafted email, executing malicious scripts without any further user interaction.