An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 8.8.15. XSS can occur, via one of attributes of the webmail /h/ endpoint, to execute arbitrary JavaScript code, leading to information disclosure.
| Software | From | Fixed in |
|---|---|---|
| zimbra / collaboration | 9.0.0 | 9.0.0.x |
| zimbra / collaboration | 9.0.0-p2 | 9.0.0-p2.x |
| zimbra / collaboration | 9.0.0-p3 | 9.0.0-p3.x |
| zimbra / collaboration | 9.0.0-p4 | 9.0.0-p4.x |
| zimbra / collaboration | 9.0.0-p5 | 9.0.0-p5.x |
| zimbra / collaboration | 9.0.0-p6 | 9.0.0-p6.x |
| zimbra / collaboration | 9.0.0-p7 | 9.0.0-p7.x |
| zimbra / collaboration | 9.0.0-p8 | 9.0.0-p8.x |
| zimbra / collaboration | 9.0.0-p9 | 9.0.0-p9.x |
| zimbra / collaboration | 9.0.0-p1 | 9.0.0-p1.x |
| zimbra / collaboration | 9.0.0-p10 | 9.0.0-p10.x |
| zimbra / collaboration | 9.0.0-p11 | 9.0.0-p11.x |
| zimbra / collaboration | 9.0.0-p12 | 9.0.0-p12.x |
| zimbra / collaboration | 9.0.0-p13 | 9.0.0-p13.x |
| zimbra / collaboration | 9.0.0-p14 | 9.0.0-p14.x |
| zimbra / collaboration | 9.0.0-p15 | 9.0.0-p15.x |
| zimbra / collaboration | 9.0.0-p0 | 9.0.0-p0.x |
| zimbra / collaboration | 9.0.0-p19 | 9.0.0-p19.x |
| zimbra / collaboration | 9.0.0-p23 | 9.0.0-p23.x |
| zimbra / collaboration | 9.0.0-p25 | 9.0.0-p25.x |
| zimbra / collaboration | 9.0.0-p26 | 9.0.0-p26.x |
| zimbra / collaboration | 9.0.0-p27 | 9.0.0-p27.x |
| zimbra / collaboration | 9.0.0-p7.1 | 9.0.0-p7.1.x |