Reflected Cross-Site Scripting Vulnerability in Zimbra Collaboration Suite
CVE-2024-50599

Currently unrated

Key Information:

Vendor

Zimbra

Vendor
CVE Published:
7 November 2024

What is CVE-2024-50599?

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Zimbra Collaboration Suite, specifically affecting the webmail calendar endpoints. This vulnerability arises due to improper handling of user-supplied input, enabling attackers to inject malicious scripts that are reflected back to users in the HTML response. Successful exploitation could lead to unauthorized actions on behalf of users, potentially compromising sensitive information and user accounts.

References

Timeline

  • Vulnerability published

.