在 Zimbra Collaboration(ZCS)10.1.17 之前的版本中,Zimbra 经典 Web 客户端存在一个存储型跨站脚本(XSS)漏洞。该漏洞源于对特定附件内容在Inline预览时的清理不足。攻击者可发送包含恶意附件的构造邮件,当用户预览该邮件时,会在受害者的浏览器会话中执行任意 JavaScript 代码。成功利用此漏洞后,攻击者可以代表受害者用户执行未授权操作,可能导致数据泄露或对敏感信息的未授权访问。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Zimbra | Collaboration | < 10.1.17 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Zimbra | Collaboration | 0 ~ 10.1.17 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73570 | 8.9 HIGH | Zimbra Collaboration 命令注入漏洞 |
| CVE-2026-73576 | 6.3 MEDIUM | Zimbra <10.1.17 OnlyOffice弱密钥生成致JWT伪造 |
| CVE-2026-73575 | 3.1 LOW | ZCS<10.1.17 CSRF漏洞 |
| CVE-2026-73573 | 3.1 LOW | Zimbra Collaboration <10.1.17 路径穿越漏洞 |
| CVE-2026-73571 | 3.1 LOW | Zimbra Collaboration <10.1.17 授权绕过漏洞 |
| CVE-2026-73574 | 3.1 LOW | Zimbra<10.1.17经典Web客户端LFI漏洞 |
No comments yet