CVE-2023-34192
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
A security flaw in Zimbra ZCS 8.8.15 allows an authenticated user to inject malicious scripts through the auto-save draft feature, which get executed in other users' browsers. This can lead to account takeover or data theft.
Cross-Site Scripting (XSS) vulnerability in the /h/autoSaveDraft endpoint of Zimbra ZCS 8.8.15 allows an authenticated attacker to inject arbitrary JavaScript code that executes in the context of other users' sessions. The vulnerability requires prior authentication and can result in session hijacking, credential theft, or malware distribution within the email system.
The full analysis of this CVE is available in Portuguese →