未经身份验证的日历发送者可以在 COUNTER 消息的 RFC From 地址中注入可执行的标记内容。在 Zimbra Classic 中选中该消息时,会触发存储型跨站脚本漏洞(Stored XSS),使攻击者能够访问用户的邮箱数据,并以受害者身份进行操作。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Zimbra | Zimbra Collaboration Suite (ZCS) | < 10.1.21 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Zimbra | Zimbra Collaboration Suite (ZCS) | 0 ~ 10.1.21 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93643 | 9.8 CRITICAL | Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code Ex |
| CVE-2026-93642 | 9.3 CRITICAL | Zimbra Collaboration Suite Modern Web Client Stored Cross-Site Scripting via Forged Share |
| CVE-2026-93641 | 9.3 CRITICAL | Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Forged Share |
No comments yet