Zimbra urges customers to patch critical web client XSS flaw
ID: fa034272-0cb7-5d53-94c2-aca7e85bda7f
STIX ID: report--fa034272-0cb7-5d53-94c2-aca7e85bda7f
Feed Name: Bleeping Computer
Threat Score
Zimbra released ZCS v10.1.19 to patch a critical stored XSS vulnerability in its Classic Web Client that can be triggered by specially crafted emails to steal session data, account settings, or mailbox content; the flaw was reported by Google's Threat Analysis Group and, while not yet confirmed as exploited in the wild, is highlighted as high-risk given prior widespread abuse of Zimbra vulnerabilities by Russian state-linked APTs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
