Zimbra 10.1.20 Fixes Critical SNMP Command Injection and Multiple XSS Flaws
ID: 7021791d-d2f8-512b-b53a-dbaaf0d49bc9
STIX ID: report--7021791d-d2f8-512b-b53a-dbaaf0d49bc9
Feed Name: GBHackers
Threat Score
Zimbra released version 10.1.20 addressing multiple high-severity vulnerabilities — notably a critical command-injection in the SNMP monitoring component when SNMP notifications are enabled, multiple stored/reflected XSS flaws in the Classic Web Client, an SSRF in Nextcloud integration, a mail-forwarding restriction bypass, and EWS/mailbox access-control fixes — and urges administrators to apply the update and review SNMP and web-client exposure immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
