CVE-2023-45207
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
13/02/2024
Last modified:
27/03/2025
Description
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. An attacker can send a PDF document through mail that contains malicious JavaScript. While previewing this file in webmail in the Chrome browser, the stored XSS payload is executed. (This has been mitigated by sanitising the JavaScript code present in a PDF document.)
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:zimbra:collaboration:*:*:*:*:*:*:*:* | 10.0.0 (including) | 10.0.5 (excluding) |
| cpe:2.3:a:zimbra:collaboration:8.8.15:-:*:*:*:*:*:* | ||
| cpe:2.3:a:zimbra:collaboration:8.8.15:p1:*:*:*:*:*:* | ||
| cpe:2.3:a:zimbra:collaboration:8.8.15:p10:*:*:*:*:*:* | ||
| cpe:2.3:a:zimbra:collaboration:8.8.15:p11:*:*:*:*:*:* | ||
| cpe:2.3:a:zimbra:collaboration:8.8.15:p12:*:*:*:*:*:* | ||
| cpe:2.3:a:zimbra:collaboration:8.8.15:p13:*:*:*:*:*:* | ||
| cpe:2.3:a:zimbra:collaboration:8.8.15:p14:*:*:*:*:*:* | ||
| cpe:2.3:a:zimbra:collaboration:8.8.15:p15:*:*:*:*:*:* | ||
| cpe:2.3:a:zimbra:collaboration:8.8.15:p16:*:*:*:*:*:* | ||
| cpe:2.3:a:zimbra:collaboration:8.8.15:p17:*:*:*:*:*:* | ||
| cpe:2.3:a:zimbra:collaboration:8.8.15:p18:*:*:*:*:*:* | ||
| cpe:2.3:a:zimbra:collaboration:8.8.15:p19:*:*:*:*:*:* | ||
| cpe:2.3:a:zimbra:collaboration:8.8.15:p2:*:*:*:*:*:* | ||
| cpe:2.3:a:zimbra:collaboration:8.8.15:p20:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://wiki.zimbra.com/wiki/Security_Center
- https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
- https://wiki.zimbra.com/wiki/Security_Center
- https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories



