MEDIUM

CVE-2022-27926

Synacor Zimbra Collaboration Suite 2022-04-21 CVSS v3.1
CVSS
6.1
KEV

Description

A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated attackers to execute arbitrary web script or HTML via request parameters.

Summary dbcve.org

A reflected cross-site scripting (XSS) vulnerability exists in the /public/launchNewWindow.jsp component of Zimbra Collaboration Suite 9.0. The vulnerability allows unauthenticated attackers to inject malicious JavaScript or HTML through unsanitized request parameters that get reflected back in the HTTP response.

Mitigation

Apply vendor-provided patches for CVE-2022-27926 or upgrade to a patched version of ZCS. As an interim control, consider restricting access to the affected /public/launchNewWindow.jsp endpoint until the patch can be applied.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

17.63%
Probability of exploitation in next 30 days
97th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE