CVE-2021-35207

CVE-2021-35207

An issue was discovered in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.0 before 9.0.0 Patch 16. An XSS vulnerability exists in the login component of Zimbra Web Client, in which an attacker can execute arbitrary JavaScript by adding executable JavaScript to the loginErrorCode parameter of the login url.

Source: CVE-2021-35207

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다