CVE-2023-43102: Zimbra Collaboration
Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.
An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.4. An XSS issue can be exploited to access the mailbox of an authenticated user. This is also fixed in 8.8.15 Patch 43 and 9.0.0 Patch 36.
Affected products
- Zimbra Collaboration: before 8.8.15 (fixed in 8.8.15); from 10.0.0, before 10.0.4 (fixed in 10.0.4); version 8.8.15 only; version 9.0.0 only
Published 2023-12-07. Last modified 2026-06-17.