Medium severity6.1NVD Advisory· Published Dec 15, 2021· Updated Jun 17, 2026
CVE-2020-18984
CVE-2020-18984
Description
A reflected cross-site scripting (XSS) vulnerability in the zimbraAdmin/public/secureRequest.jsp component of Zimbra Collaboration 8.8.12 allows unauthenticated attackers to execute arbitrary web scripts or HTML via a host header injection.
Affected products
3- Zimbra/Zimbra Collaborationdescription
- cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.12:-:*:*:*:*:*:*
- Range: = 8.8.12
Patches
Vulnerability mechanics
References
1- github.com/buxu/bug/issues/2nvdIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.