Executive brief
A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration Suite (ZCS) allows unauthenticated attackers to execute arbitrary web script or HTML via unsanitized request parameters. This vulnerability has been observed being exploited in the wild.
Affected products
- Synacor Zimbra Collaboration Suite (ZCS) 9.0.0 up to Patch 23
Timeline
- 2022-04-28: disclosed: Initial NIST analysis date
- 2023-04-03: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog