In Zimbra Collaboration Suite (ZCS) 8.8.15, at the URL /h/calendar, one can trigger XSS by adding JavaScript code to the view parameter and changing the value of the uncheck parameter to a string (instead of default value of 10).
{ "versions": [ { "introduced": "0" }, { "last_affected": "8.8.15-NA" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-41351.json"