CVE-2023-34192criticalunder attackCWE-79

CVE-2023-34192

Published · Updated

95Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9epss 77%
from disclosure to weapon
Published on NVDJul 6
CISA KEV+600d
exploitation probability
77%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2025-03-18

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

In short

A security flaw in Zimbra ZCS 8.8.15 allows an authenticated user to inject malicious scripts through the auto-save draft feature, which get executed in other users' browsers. This can lead to account takeover or data theft.

Technical detail

Cross-Site Scripting (XSS) vulnerability in the /h/autoSaveDraft endpoint of Zimbra ZCS 8.8.15 allows an authenticated attacker to inject arbitrary JavaScript code that executes in the context of other users' sessions. The vulnerability requires prior authentication and can result in session hijacking, credential theft, or malware distribution within the email system.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Affected products
n/a · n/a