CVE-2024-27443: Zimbra Collaboration – Cross-Site Scripting (XSS)

CVE-2024-27443: Zimbra Collaboration - Cross-Site Scripting (XSS)-渗透云记 - 专注于网络安全与技术分享
CVE-2024-27443: Zimbra Collaboration – Cross-Site Scripting (XSS)
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2024-27443: Zimbra Collaboration – Cross-Site Scripting (xss)

漏洞描述

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享