Triple Threat Patched: Zimbra 10.1.16 Fixes XSS, XXE & LDAP Injection
ID: 892e564c-b0ed-58bc-b28d-d0ff14eb412a
STIX ID: report--892e564c-b0ed-58bc-b28d-d0ff14eb412a
Feed Name: securityonline.info
Zimbra 10.1.16 was released to address several security issues — notably Cross-Site Scripting (XSS) in Webmail/Briefcase, an authenticated LDAP injection, and an XML External Entity (XXE) vulnerability in the EWS SOAP endpoint — along with strengthened CSRF protection and restored features implemented with security safeguards; administrators and users are strongly advised to upgrade immediately to mitigate risks like session hijacking, unauthorized directory access, and potential local file disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
