Synacor Zimbra Mail Client 8.6 before 8.6.0 Patch 5 has XSS via the error/warning dialog and email body content in Zimbra.
| Software | From | Fixed in |
|---|---|---|
| synacor / zimbra_collaboration_suite | 8.6.0 | 8.6.0.x |
| synacor / zimbra_collaboration_suite | 8.6.0-p1 | 8.6.0-p1.x |
| synacor / zimbra_collaboration_suite | 8.6.0-p2 | 8.6.0-p2.x |
| synacor / zimbra_collaboration_suite | 8.6.0-p3 | 8.6.0-p3.x |
| synacor / zimbra_collaboration_suite | 8.6.0-p4 | 8.6.0-p4.x |