vulnerability
Zimbra Collaboration: CVE-2023-37580: Collaboration: Cross-site Scripting
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 4 | (AV:N/AC:M/Au:N/C:P/I:N/A:N) | Jul 31, 2023 | Jan 23, 2024 | Mar 25, 2026 |
Severity
4
CVSS
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
Published
Jul 31, 2023
Added
Jan 23, 2024
Modified
Mar 25, 2026
Description
A cross-site scripting (XSS) vulnerability that was present in the in the Zimbra Classic Web Client has been addressed.
Solution
zimbra-collaboration-upgrade-latest
References
- CWE-79
- CVE-2023-37580
- https://attackerkb.com/topics/CVE-2023-37580
- http://www.openwall.com/lists/oss-security/2023/11/17/2
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-41465
- https://wiki.zimbra.com/wiki/Security_Center
- https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.