CVE-2022-27926
Description
A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated attackers to execute arbitrary web script or HTML via request parameters.
Summary dbcve.org
A reflected cross-site scripting (XSS) vulnerability exists in the /public/launchNewWindow.jsp component of Zimbra Collaboration Suite 9.0. The vulnerability allows unauthenticated attackers to inject malicious JavaScript or HTML through unsanitized request parameters that get reflected back in the HTTP response.
Mitigation
Apply vendor-provided patches for CVE-2022-27926 or upgrade to a patched version of ZCS. As an interim control, consider restricting access to the affected /public/launchNewWindow.jsp endpoint until the patch can be applied.