In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/search?action accepts parameters called extra, title, and onload that are partially sanitised and lead to reflected XSS that allows executing arbitrary JavaScript on the victim's machine.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-08-11T19:44:46

Updated: 2022-08-11T19:44:46

Reserved: 2022-08-01T00:00:00


Link: CVE-2022-37044

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-08-12T15:15:16.137

Modified: 2022-08-16T15:18:02.307


Link: CVE-2022-37044

JSON object: View

cve-icon Redhat Information

No data.

CWE