vulnerability

Zimbra Collaboration: CVE-2024-50599: Reflected Cross-Site Scripting (XSS) Vulnerability

Severity
6
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:N)
Published
Nov 7, 2024
Added
Jan 10, 2025
Modified
Jul 17, 2025

Description

A reflected cross-site scripting (xss) vulnerability has been identified in zimbra collaboration suite (zcs) 8.8.15, affecting one of the webmail calendar endpoints. this arises from improper handling of user-supplied input, allowing an attacker to inject malicious code that is reflected back in the html response.

Solution

zimbra-collaboration-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.