Record summary

CVE-2023-34192 has a selected CVSS score of 9.0 (critical); EIP currently links 1 Nuclei template. CISA lists CVE-2023-34192 in KEV.

Description

Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Feb 25, 2025 · CISA
VulnCheck KEV
Listed · Feb 25, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 25, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CISAVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALZimbra Collaboration Suite (ZCS) v.8.8.15 - Cross-Site ScriptingCVSS 9

Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Apply the latest security patches or upgrade to a non-vulnerable version of Zimbra Collaboration Suite (ZCS).

WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2023zimbraxssauthenticatedkevvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CPE: cpe:2.3:a:zimbra:collaboration:8.8.15:-:*:*:*:*:*:*
Shodan: http.favicon.hash:475145467
Shodan: http.favicon.hash:"1624375939"
Shodan: http.favicon.hash:"475145467"
FOFA: icon_hash="475145467"
FOFA: icon_hash="1624375939"
FOFA: app="zimbra-邮件系统"

Source: ProjectDiscovery

References

5