An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur on the Classic UI login page by injecting arbitrary JavaScript code in the username field. This occurs before the user logs into the system, which means that even if the attacker executes arbitrary JavaScript, they will not get any sensitive information.
Metrics
Affected Vendors & Products
References
History
Wed, 09 Apr 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-09T20:31:37.345Z
Reserved: 2022-11-26T00:00:00.000Z
Link: CVE-2022-45911

Updated: 2024-08-03T14:24:03.221Z

Status : Modified
Published: 2023-01-06T23:15:09.673
Modified: 2025-04-09T21:15:42.780
Link: CVE-2022-45911

No data.