CVE-2022-24682: Zimbra Collaboration Suite < 8.8.15 - Improper Encoding

CVE-2022-24682: Zimbra Collaboration Suite < 8.8.15 - Improper Encoding-渗透云记 - 专注于网络安全与技术分享
CVE-2022-24682: Zimbra Collaboration Suite < 8.8.15 - Improper Encoding
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2022-24682: Zimbra Collaboration Suite < 8.8.15 – Improper Encoding

漏洞描述

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享