A high-severity Cross-Site Scripting (XSS) vulnerability (CVSS 8.1) in the Synacor Zimbra Classic Web Client allows a remote, anonymous attacker to execute arbitrary scripts. The vulnerability affects Zimbra Classic Web Client versions prior to 10.1.19. A mitigation is available, and users should upgrade to version 10.1.19 to resolve the issue.
[WID-SEC-2026-2216] Synacor Zimbra Classic Web Client: Schwachstelle ermöglicht Cross-Site Scripting CVSS Base Score 8.1 (hoch) CVSS Temporal Score 7.1 (hoch) Remoteangriff ja Datum 06.07.2026 Stand 07.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges UNIX Produktbeschreibung Zimbra ist eine Groupware-Lösung, die E-Mail, Kalender und Aufgabenverwaltung bietet. Produkte 06.07.2026 Synacor Zimbra Classic Web Client <10.1.19 Angriff Angriff Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Synacor Zimbra Classic Web Client ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben