Vulnerability Details CVE-2023-34192
Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.863
EPSS Ranking 99.4%
CVSS Severity
CVSS v3 Score 9.0
Proposed Action
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability that allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.
Ransomware Campaign
Unknown
Products affected by CVE-2023-34192
-
cpe:2.3:a:zimbra:collaboration:8.8.15