ZIMBRA recently released patches for several critical vulnerabilities in its Collaboration Suite (ZCS) version 10.1.20, addressing a command injection issue, multiple cross-site scripting (XSS) flaws, and access control vulnerabilities. These vulnerabilities could allow unauthorized attackers to execute OS commands, bypass email forwarding restrictions, and exploit server-side request forgery bugs. Although Zimbra has not confirmed any active exploitation of these issues, users are urged to update to the latest version immediately.
Zimbra fixes critical command injection, XSS flaws in ZCS 10.1.20
CyberSIXT Evidence Panel
Primary Source
blog.zimbra.com
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Zimbra patches critical SNMP command injection and four XSS flaws
thehackernews.com
-
Zimbra fixes critical command injection, XSS flaws in ZCS 10.1.20
www.securityweek.com
-
Zimbra XSS flaw lets attackers take over accounts with zero click
securityweek.com