未认证的攻击者可以伪造共享通知,该通知会在已登录的 Zimbra Modern 收件人点击“接受共享”时触发存储型跨站脚本(XSS)漏洞,从而使攻击者能够访问邮件箱数据并冒充受害者进行操作。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Zimbra | Zimbra Collaboration Suite (ZCS) | < 10.1.21 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Zimbra | Zimbra Collaboration Suite (ZCS) | 0 ~ 10.1.21 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93643 | 9.8 CRITICAL | Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code Ex |
| CVE-2026-93647 | 9.3 CRITICAL | Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Crafted Cale |
| CVE-2026-93641 | 9.3 CRITICAL | Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Forged Share |
No comments yet