未经身份验证的攻击者可以伪造一份共享通知,当已登录的 Zimbra Classic 收件人点击“接受共享”时,该通知将触发存储型跨站脚本攻击(XSS)。利用此漏洞,攻击者能够访问受害者的邮箱数据,并以受害者身份执行操作。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Zimbra | Zimbra Collaboration Suite (ZCS) | < 10.1.21 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Zimbra | Zimbra Collaboration Suite (ZCS) | 0 ~ 10.1.21 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93643 | 9.8 CRITICAL | Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code Ex |
| CVE-2026-93642 | 9.3 CRITICAL | Zimbra Collaboration Suite Modern Web Client Stored Cross-Site Scripting via Forged Share |
| CVE-2026-93647 | 9.3 CRITICAL | Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Crafted Cale |
No comments yet