Zarafa WebApp 2.0.1.47791 and earlier contains an unauthenticated reflected cross-site scripting vulnerability. An attacker can execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site.
id: CVE-2019-7219
info:
name: Zarafa WebApp <=2.0.1.47791 - Cross-Site Scripting
author: pdteam
...