An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. Through the help document endpoint in webmail, an attacker can inject JavaScript or HTML code that leads to cross-site scripting (XSS). (Adding an adequate message to avoid malicious code will mitigate this issue.)
| Software | From | Fixed in |
|---|---|---|
| zimbra / collaboration | 9.0.0 | 9.0.0.x |
| zimbra / collaboration | 9.0.0-p2 | 9.0.0-p2.x |
| zimbra / collaboration | 9.0.0-p3 | 9.0.0-p3.x |
| zimbra / collaboration | 9.0.0-p4 | 9.0.0-p4.x |
| zimbra / collaboration | 9.0.0-p5 | 9.0.0-p5.x |
| zimbra / collaboration | 9.0.0-p6 | 9.0.0-p6.x |
| zimbra / collaboration | 9.0.0-p1 | 9.0.0-p1.x |
| zimbra / collaboration | 9.0.0-p9 | 9.0.0-p9.x |
| zimbra / collaboration | 9.0.0-p8 | 9.0.0-p8.x |
| zimbra / collaboration | 9.0.0-p7 | 9.0.0-p7.x |
| zimbra / collaboration | 8.8.15-p1 | 8.8.15-p1.x |
| zimbra / collaboration | 8.8.15-p12 | 8.8.15-p12.x |
| zimbra / collaboration | 8.8.15-p13 | 8.8.15-p13.x |
| zimbra / collaboration | 8.8.15-p14 | 8.8.15-p14.x |
| zimbra / collaboration | 8.8.15-p15 | 8.8.15-p15.x |
| zimbra / collaboration | 8.8.15-p16 | 8.8.15-p16.x |
| zimbra / collaboration | 8.8.15-p11 | 8.8.15-p11.x |
| zimbra / collaboration | 8.8.15-p10 | 8.8.15-p10.x |
| zimbra / collaboration | 8.8.15-p8 | 8.8.15-p8.x |
| zimbra / collaboration | 8.8.15-p9 | 8.8.15-p9.x |
| zimbra / collaboration | 8.8.15-p7 | 8.8.15-p7.x |
| zimbra / collaboration | 8.8.15-p17 | 8.8.15-p17.x |
| zimbra / collaboration | 8.8.15-p18 | 8.8.15-p18.x |
| zimbra / collaboration | 8.8.15-p19 | 8.8.15-p19.x |
| zimbra / collaboration | 9.0.0-p10 | 9.0.0-p10.x |
| zimbra / collaboration | 9.0.0-p11 | 9.0.0-p11.x |
| zimbra / collaboration | 9.0.0-p12 | 9.0.0-p12.x |
| zimbra / collaboration | 9.0.0-p13 | 9.0.0-p13.x |
| zimbra / collaboration | 9.0.0-p14 | 9.0.0-p14.x |
| zimbra / collaboration | 9.0.0-p15 | 9.0.0-p15.x |
| zimbra / collaboration | 8.8.15-p20 | 8.8.15-p20.x |
| zimbra / collaboration | 8.8.15-p21 | 8.8.15-p21.x |
| zimbra / collaboration | 8.8.15-p22 | 8.8.15-p22.x |
| zimbra / collaboration | 8.8.15-p23 | 8.8.15-p23.x |
| zimbra / collaboration | 8.8.15-p24 | 8.8.15-p24.x |
| zimbra / collaboration | 8.8.15-p25 | 8.8.15-p25.x |
| zimbra / collaboration | 8.8.15-p6 | 8.8.15-p6.x |
| zimbra / collaboration | 8.8.15-p5 | 8.8.15-p5.x |
| zimbra / collaboration | 8.8.15-p4 | 8.8.15-p4.x |
| zimbra / collaboration | 8.8.15-p3 | 8.8.15-p3.x |
| zimbra / collaboration | 8.8.15-p2 | 8.8.15-p2.x |
| zimbra / collaboration | 8.8.15 | 8.8.15.x |
| zimbra / collaboration | 8.8.15-p26 | 8.8.15-p26.x |
| zimbra / collaboration | 8.8.15-p27 | 8.8.15-p27.x |
| zimbra / collaboration | 8.8.15-p28 | 8.8.15-p28.x |
| zimbra / collaboration | 8.8.15-p29 | 8.8.15-p29.x |
| zimbra / collaboration | 8.8.15-p30 | 8.8.15-p30.x |
| zimbra / collaboration | 8.8.15-p31 | 8.8.15-p31.x |
| zimbra / collaboration | 8.8.15-p32 | 8.8.15-p32.x |
| zimbra / collaboration | 8.8.15-p33 | 8.8.15-p33.x |
| zimbra / collaboration | 8.8.15-p34 | 8.8.15-p34.x |
| zimbra / collaboration | 9.0.0-p0 | 9.0.0-p0.x |
| zimbra / collaboration | 9.0.0-p19 | 9.0.0-p19.x |
| zimbra / collaboration | 9.0.0-p23 | 9.0.0-p23.x |
| zimbra / collaboration | 9.0.0-p25 | 9.0.0-p25.x |
| zimbra / collaboration | 9.0.0-p26 | 9.0.0-p26.x |
| zimbra / collaboration | 9.0.0-p27 | 9.0.0-p27.x |
| zimbra / collaboration | 9.0.0-p7.1 | 9.0.0-p7.1.x |
| zimbra / collaboration | 9.0.0-p24.1 | 9.0.0-p24.1.x |
| zimbra / collaboration | 9.0.0-p24 | 9.0.0-p24.x |
| zimbra / collaboration | 9.0.0-p16 | 9.0.0-p16.x |
| zimbra / collaboration | 9.0.0-p21 | 9.0.0-p21.x |
| zimbra / collaboration | 9.0.0-p20 | 9.0.0-p20.x |
| zimbra / collaboration | 9.0.0-p33 | 9.0.0-p33.x |
| zimbra / collaboration | 8.8.15-p35 | 8.8.15-p35.x |
| zimbra / collaboration | 8.8.15-p37 | 8.8.15-p37.x |
| zimbra / collaboration | 8.8.15-p40 | 8.8.15-p40.x |
| zimbra / collaboration | 8.8.15-p41 | 8.8.15-p41.x |
| zimbra / collaboration | 9.0.0-p34 | 9.0.0-p34.x |
| zimbra / collaboration | 9.0.0-p35 | 9.0.0-p35.x |
| zimbra / collaboration | 8.8.15-p42 | 8.8.15-p42.x |
| zimbra / collaboration | 9.0.0-p36 | 9.0.0-p36.x |
| zimbra / collaboration | 9.0.0-p30 | 9.0.0-p30.x |
| zimbra / collaboration | 9.0.0-p31 | 9.0.0-p31.x |
| zimbra / collaboration | 9.0.0-p32 | 9.0.0-p32.x |
| zimbra / collaboration | 8.8.15-p43 | 8.8.15-p43.x |
| zimbra / collaboration | 10.0.0 | 10.0.5 |
| zimbra / collaboration | 8.8.15-p38 | 8.8.15-p38.x |
| zimbra / collaboration | 8.8.15-p39 | 8.8.15-p39.x |