CVE-2023-37580: Zimbra XSS Vulnerability Exploited by Threat Actors
A cross-site scripting vulnerability in Zimbra that was exploited by threat actors. Part of a series of XSS flaws targeting Zimbra's web…
A cross-site scripting vulnerability in Zimbra that was exploited by threat actors. Part of a series of XSS flaws targeting Zimbra's web…
A cross-site scripting vulnerability in Zimbra that was exploited by threat actors. Part of a series of XSS flaws targeting Zimbra's web…
The Classic Web Client in Zimbra had four XSS vulnerabilities patched, including stored XSS via attachment filenames and crafted fields.
Zimbra has disclosed a critical stored cross-site scripting (XSS) vulnerability in its Classic Web Client that could allow attackers to execute arbitrary…
A stored cross-site scripting (XSS) vulnerability in Zimbra's Classic Web Client (CVSS 5.4) that was allegedly exploited as a zero-day against the…
A newly identified cyber attack campaign, tracked as StrikeShark by Kaspersky, is deploying a previously undocumented malware family called SharkLoader to deliver…
CVE-2022-27925 is a vulnerability in Zimbra Collaboration Suite that allows remote code execution. It was used in the StrikeShark campaign.
Zimbra provides email and collaboration software. It recently patched multiple critical vulnerabilities including SNMP command injection and XSS flaws.
Zimbra's flagship product offering email, calendar, and collaboration features. Version 10.1.19 includes a fix for a critical stored XSS vulnerability in the…