U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-45194

Change History

New CVE Received from MITRE 11/21/2024 12:15:15 PM

Action Type Old Value New Value
Added Description

								
							
							
						
In Zimbra Collaboration (ZCS) 9.0 and 10.0, a vulnerability in the Webmail Modern UI allows execution of stored Cross-Site Scripting (XSS) payloads. An attacker with administrative access to the Zimbra Administration Panel can inject malicious JavaScript code while configuring an email account. This injected code is stored on the server and executed in the context of the victim's browser when interacting with specific elements in the web interface. (The vulnerability can be mitigated by properly sanitizing input parameters to prevent the injection of malicious code.)
Added Reference

								
							
							
						
https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.9#Security_Fixes
Added Reference

								
							
							
						
https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.1#Security_Fixes
Added Reference

								
							
							
						
https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P41#Security_Fixes
Added Reference

								
							
							
						
https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy