CVE-2019-7219: Zarafa Webaccess

Medium severity, CVSS 6.1. EPSS: 5% chance of exploitation in the next 30 days.

Unauthenticated reflected cross-site scripting (XSS) exists in Zarafa Webapp 2.0.1.47791 and earlier. NOTE: this is a discontinued product. The issue was fixed in later Zarafa Webapp versions; however, some former Zarafa Webapp customers use the related Kopano product instead.

Affected products

  • Zarafa Webaccess: version 7.2.0-48204 only

Published 2019-04-11. Last modified 2026-06-17.