VYPR

Collaboration Server

by Zimbra

Source repositories

CVEs (37)

  • CVE-2022-41349MedOct 12, 2022
    risk 0.40cvss 6.1epss 0.00

    In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/compose accepts an attachUrl parameter that is vulnerable to Reflected XSS. This allows executing arbitrary JavaScript on the victim's machine.

  • CVE-2022-37044MedAug 12, 2022
    risk 0.40cvss 6.1epss 0.01

    In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/search?action accepts parameters called extra, title, and onload that are partially sanitised and lead to reflected XSS that allows executing arbitrary JavaScript on the victim's machine.

  • CVE-2019-8947MedJan 27, 2020
    risk 0.40cvss 6.1epss 0.01

    Zimbra Collaboration 8.7.x - 8.8.11P2 contains non-persistent XSS.

  • CVE-2019-8946MedJan 27, 2020
    risk 0.40cvss 6.1epss 0.01

    Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS.

  • CVE-2019-8945MedJan 27, 2020
    risk 0.40cvss 6.1epss 0.01

    Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS.

  • CVE-2019-15313MedJan 27, 2020
    risk 0.40cvss 6.1epss 0.01

    In Zimbra Collaboration before 8.8.15 Patch 1, there is a non-persistent XSS vulnerability.

  • CVE-2015-2230MedMay 30, 2019
    risk 0.40cvss 6.1epss 0.01

    Synacor Zimbra Collaboration Server 8.x before 8.7.0 has Reflected XSS in admin console.

  • CVE-2016-5721MedAug 29, 2016
    risk 0.40cvss 6.1epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2022-37043MedAug 12, 2022
    risk 0.37cvss 5.7epss 0.00

    An issue was discovered in the webmail component in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. When using preauth, CSRF tokens are not checked on some POST endpoints. Thus, when an authenticated user views an attacker-controlled page, a request will be sent to the…

  • CVE-2024-45512MedNov 21, 2024
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in webmail in Zimbra Collaboration (ZCS) through 10.1. An attacker can exploit this vulnerability by creating a folder in the Briefcase module with a malicious payload and sharing it with a victim. When the victim interacts with the folder share…

  • CVE-2024-33536MedAug 12, 2024
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The vulnerability occurs due to inadequate input validation of the res parameter, allowing an authenticated attacker to inject and execute arbitrary JavaScript code within the context of another user's browser…

  • CVE-2018-10949MedMay 10, 2018
    risk 0.35cvss 5.3epss 0.02

    mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the "HTTP 404 - account is not active" and "HTTP 401 - must authenticate" errors.

  • CVE-2025-25065MedFeb 3, 2025
    risk 0.34cvss 5.3epss 0.01

    SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4 allows unauthorized redirection to internal network endpoints.

  • CVE-2019-12427MedJan 27, 2020
    risk 0.31cvss 4.8epss 0.01

    Zimbra Collaboration before 8.8.15 Patch 1 is vulnerable to a non-persistent XSS via the Admin Console.

  • CVE-2013-7217Dec 26, 2013
    risk 0.00cvss epss 0.03

    Unspecified vulnerability in Zimbra Collaboration Server 7.2.5 and earlier, and 8.0.x through 8.0.5, has "critical" impact and unspecified vectors, a different vulnerability than CVE-2013-7091.

  • CVE-2008-1226Mar 10, 2008
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration Suite (ZCS) 4.0.3, 4.5.6, and possibly other versions before 4.5.10 allow remote attackers to inject arbitrary web script or HTML via an e-mail attachment, possibly involving a (1) .jpg or (2) .gif image…

  • CVE-2007-0284Jan 17, 2007
    risk 0.00cvss epss 0.02

    Multiple unspecified vulnerabilities in Oracle Application Server 9.0.4.3 and 10.1.2.0.0, and Collaboration Suite 9.0.4.2, have unknown impact and attack vectors related to Oracle Containers for J2EE, aka (1) OC4J03 and (2) OC4J04.

Page 2 of 2