CVE-2022-45911
 
Severity Score
6.1
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur on the Classic UI login page by injecting arbitrary JavaScript code in the username field. This occurs before the user logs into the system, which means that even if the attacker executes arbitrary JavaScript, they will not get any sensitive information.
Se descubrió un problema en Zimbra Collaboration (ZCS) 9.0. XSS puede ocurrir en la página de inicio de sesión de la IU clásica inyectando código JavaScript arbitrario en el campo username. Esto ocurre antes de que el usuario inicie sesión en el sistema, lo que significa que incluso si el atacante ejecuta JavaScript arbitrario, no obtendrá ninguna información confidencial.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-11-26 CVE Reserved
- 2023-01-06 CVE Published
- 2024-07-29 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://wiki.zimbra.com/wiki/Security_Center | 2023-01-12 | |
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories | 2023-01-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | - |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p0 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p1 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p10 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p11 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p12 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p13 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p14 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p15 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p16 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p19 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p2 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p20 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p21 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p23 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p24 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p24.1 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p25 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p26 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p27 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p3 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p4 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p5 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p6 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p7 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p7.1 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p8 |
Affected
| ||||||
Zimbra Search vendor "Zimbra" | Collaboration Search vendor "Zimbra" for product "Collaboration" | 9.0.0 Search vendor "Zimbra" for product "Collaboration" and version "9.0.0" | p9 |
Affected
|