EUVD-2023-38291
Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 25 Feb 2025. Evidence sources: cisa_kev.
- ENISA score
- 9.0 · CVSS 3.1
- Advisory evidence
- No linked advisory details stored yet
