Reflected XSS Vulnerability in Zimbra Collaboration Suite (ZCS) 8.8.15

Reflected XSS Vulnerability in Zimbra Collaboration Suite (ZCS) 8.8.15

CVE-2022-37044 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/search?action accepts parameters called extra, title, and onload that are partially sanitised and lead to reflected XSS that allows executing arbitrary JavaScript on the victim's machine.

Learn more about our Web Application Penetration Testing UK.