zimbra collaboration CVE-2021-35207 is a vulnerability in Zimbra Collaboration
Published on July 2, 2021

An issue was discovered in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.0 before 9.0.0 Patch 16. An XSS vulnerability exists in the login component of Zimbra Web Client, in which an attacker can execute arbitrary JavaScript by adding executable JavaScript to the loginErrorCode parameter of the login url.

NVD


Products Associated with CVE-2021-35207

Want to know whenever a new CVE is published for Zimbra Collaboration? stack.watch will email you.

 

Exploit Probability

EPSS
1.06%
Percentile
77.34%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.