An XSS vulnerability exists in the Webmail component of Zimbra Collaboration Suite before 8.8.15 Patch 11. It allows an attacker to inject executable JavaScript into the account name of a user’s profile. The injected code can be reflected and executed when changing an e-mail signature.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13653
Reference (s):
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P11
- https://wiki.zimbra.com/wiki/Security_Center
- https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P4
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories

