VendorsSynacorzimbra_collaboration_suite8.8.12
Vulnerabilities

Synacor Zimbra Collaboration Suite 8.8.12

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2020-18984
A reflected cross-site scripting (XSS) vulnerability in the zimbraAdmin/public/secureRequest.jsp component of Zimbra Collaboration 8.8.12 allows unauthenticated attackers to execute arbitrary web scripts or HTML via a host header injection.
Published 2021-12-15 · Modified
6.1EPSS 0.008
CVE-2020-18985
An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows attackers to redirect users to any arbitrary website of their choosing.
Published 2021-12-15 · Modified
6.1EPSS 0.007