zimbra collaboration CVE-2021-35208 is a vulnerability in Zimbra Collaboration
Published on July 2, 2021

An issue was discovered in ZmMailMsgView.js in the Calendar Invite component in Zimbra Collaboration Suite 8.8.x before 8.8.15 Patch 23. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.

NVD


Products Associated with CVE-2021-35208

Want to know whenever a new CVE is published for Zimbra Collaboration? stack.watch will email you.

 

Exploit Probability

EPSS
1.28%
Percentile
79.34%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.