An XSS vulnerability exists in the Webmail component of Zimbra Collaboration Suite before 8.8.15 Patch 11. It allows an attacker to inject executable JavaScript into the account name of a user's profile. The injected code can be reflected and executed when changing an e-mail signature.
| Software | From | Fixed in |
|---|---|---|
| synacor / zimbra_collaboration_suite | 8.8.15-p1 | 8.8.15-p1.x |
| synacor / zimbra_collaboration_suite | 8.8.15 | 8.8.15.x |
| synacor / zimbra_collaboration_suite | - | 8.8.15 |
| synacor / zimbra_collaboration_suite | 8.8.15-p6 | 8.8.15-p6.x |
| synacor / zimbra_collaboration_suite | 8.8.15-p5 | 8.8.15-p5.x |
| synacor / zimbra_collaboration_suite | 8.8.15-p3 | 8.8.15-p3.x |
| synacor / zimbra_collaboration_suite | 8.8.15-p4 | 8.8.15-p4.x |
| synacor / zimbra_collaboration_suite | 8.8.15-p2 | 8.8.15-p2.x |
| synacor / zimbra_collaboration_suite | 8.8.15-p7 | 8.8.15-p7.x |
| synacor / zimbra_collaboration_suite | 8.8.15-p8 | 8.8.15-p8.x |
| synacor / zimbra_collaboration_suite | 8.8.15-p9 | 8.8.15-p9.x |
| synacor / zimbra_collaboration_suite | 8.8.15-p10 | 8.8.15-p10.x |