Vulnerability Details CVE-2022-41349
In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/compose accepts an attachUrl parameter that is vulnerable to Reflected XSS. This allows executing arbitrary JavaScript on the victim's machine.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 72.6%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2022-41349
-
cpe:2.3:a:zimbra:collaboration:8.8.15