// For flags

CVE-2023-37580

Zimbra Collaboration (ZCS) Cross-Site Scripting (XSS) Vulnerability

Severity Score

6.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

Yes
*KEV

Decision

Track
*SSVC
Descriptions

Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.

Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability impacting the confidentiality and integrity of data.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2023-07-07 CVE Reserved
  • 2023-07-27 Exploited in Wild
  • 2023-07-31 CVE Published
  • 2023-08-17 KEV Due Date
  • 2024-09-01 EPSS Updated
  • 2024-10-18 CVE Updated
  • ---------- First Exploit
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Zimbra
Search vendor "Zimbra"
Zimbra
Search vendor "Zimbra" for product "Zimbra"
>= 8.8.0 < 8.8.15
Search vendor "Zimbra" for product "Zimbra" and version " >= 8.8.0 < 8.8.15"
-
Affected
Zimbra
Search vendor "Zimbra"
Zimbra
Search vendor "Zimbra" for product "Zimbra"
8.8.15
Search vendor "Zimbra" for product "Zimbra" and version "8.8.15"
p11
Affected
Zimbra
Search vendor "Zimbra"
Zimbra
Search vendor "Zimbra" for product "Zimbra"
8.8.15
Search vendor "Zimbra" for product "Zimbra" and version "8.8.15"
p26
Affected
Zimbra
Search vendor "Zimbra"
Zimbra
Search vendor "Zimbra" for product "Zimbra"
8.8.15
Search vendor "Zimbra" for product "Zimbra" and version "8.8.15"
p3
Affected
Zimbra
Search vendor "Zimbra"
Zimbra
Search vendor "Zimbra" for product "Zimbra"
8.8.15
Search vendor "Zimbra" for product "Zimbra" and version "8.8.15"
p30
Affected
Zimbra
Search vendor "Zimbra"
Zimbra
Search vendor "Zimbra" for product "Zimbra"
8.8.15
Search vendor "Zimbra" for product "Zimbra" and version "8.8.15"
p31
Affected
Zimbra
Search vendor "Zimbra"
Zimbra
Search vendor "Zimbra" for product "Zimbra"
8.8.15
Search vendor "Zimbra" for product "Zimbra" and version "8.8.15"
p32
Affected
Zimbra
Search vendor "Zimbra"
Zimbra
Search vendor "Zimbra" for product "Zimbra"
8.8.15
Search vendor "Zimbra" for product "Zimbra" and version "8.8.15"
p33
Affected
Zimbra
Search vendor "Zimbra"
Zimbra
Search vendor "Zimbra" for product "Zimbra"
8.8.15
Search vendor "Zimbra" for product "Zimbra" and version "8.8.15"
p34
Affected
Zimbra
Search vendor "Zimbra"
Zimbra
Search vendor "Zimbra" for product "Zimbra"
8.8.15
Search vendor "Zimbra" for product "Zimbra" and version "8.8.15"
p35
Affected
Zimbra
Search vendor "Zimbra"
Zimbra
Search vendor "Zimbra" for product "Zimbra"
8.8.15
Search vendor "Zimbra" for product "Zimbra" and version "8.8.15"
p37
Affected
Zimbra
Search vendor "Zimbra"
Zimbra
Search vendor "Zimbra" for product "Zimbra"
8.8.15
Search vendor "Zimbra" for product "Zimbra" and version "8.8.15"
p38
Affected
Zimbra
Search vendor "Zimbra"
Zimbra
Search vendor "Zimbra" for product "Zimbra"
8.8.15
Search vendor "Zimbra" for product "Zimbra" and version "8.8.15"
p40
Affected
Zimbra
Search vendor "Zimbra"
Zimbra
Search vendor "Zimbra" for product "Zimbra"
8.8.15
Search vendor "Zimbra" for product "Zimbra" and version "8.8.15"
p5
Affected