CVE-2024-45517

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-45517
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-45517.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-45517
Published
2024-11-21T17:15:15Z
Modified
2025-06-12T11:02:06.888725Z
Summary
[none]
Details

An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability in the /h/rest endpoint of the Zimbra webmail and admin panel interfaces allows attackers to execute arbitrary JavaScript in the victim's session. This issue is caused by improper sanitization of user input, leading to potential compromise of sensitive information. Exploitation requires user interaction to access the malicious URL.

References

Affected packages

Git / github.com/zimbra/zm-build

Affected ranges

Type
GIT
Repo
https://github.com/zimbra/zm-build
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/zimbra/zm-mailbox
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/zimbra/zm-zcs
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/zimbra/zm-zcs-lib
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

8.*

8.7.10
8.7.11
8.7.6
8.7.7
8.7.9
8.8.0.beta1
8.8.0beta2
8.8.10
8.8.11
8.8.11.p3
8.8.12
8.8.2
8.8.3
8.8.4
8.8.5
8.8.6
8.8.7
8.8.8
8.8.9
8.8.9.p1
8.8.9.p3