AI Stories on SHORT INFO are generated & curated with AI
unverified 18 Aug, 20:07

Critical Zimbra Classic Web Client flaw lets a crafted email run code

Zimbra has urged customers to patch a critical stored cross-site scripting flaw in its Classic Web Client that lets a specially crafted email run malicious code when opened, according to The Hacker News and Zimbra's own advisory. If exploited, it could expose mailbox data, session data, and account settings. Zimbra reports no sign of active exploitation and recommends updating to version 10.1.19.

Zimbra is urging customers to update after confirming a critical stored cross-site scripting flaw in its Classic Web Client. According to The Hacker News and Zimbra's security advisory, a specially crafted email can run malicious code in a user's session as soon as the email is opened. If exploited, an attacker could gain access to mailbox information, session data, or account settings. The flaw has not yet been assigned a CVE identifier, and Zimbra says it has no evidence of active exploitation, but its web client has been a repeated target for cross-site scripting attacks in the past. Administrators are advised to update to Zimbra Collaboration Suite version 10.1.19. Source: The Hacker News; Zimbra security advisory (release 10.1.19).

#cyber
Published on
InstagramYouTubeTikTokBlueskyX