Security Update for Zimbra Collaboration Suite Version 8.8.15
by Karyn Tan on July 13, 2023 in Product News, Product Updates, Security & Privacy
An XSS vulnerability in Zimbra Collaboration Suite Version 8.8.15 that could potentially impact the confidentiality and integrity of your data has surfaced. We take this matter very seriously and have already taken immediate action to address the issue.
- Take a backup of the file /opt/zimbra/jetty/webapps/zimbra/m/momoveto
- Edit this file and go to line number 40
- Update the parameter value as below<input name=”st” type=”hidden” value=”${fn:escapeXml(param.st)}”/>
- Before the update, the line appeared as below<input name=”st” type=”hidden” value=”${param.st}”/>
No views