CVE detail
CVE-2020-11737 — CVE-2020-11737
Published 2020-05-05 · Modified 2026-06-17 · Vendor zimbra · Product zimbra · Source nvd
MEDIUM
severity
CVSS-derived band
0.0174
EPSS probability
exploitation probability, 30d
76.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A cross-site scripting (XSS) vulnerability in Web Client in Zimbra 9.0 allows a remote attacker to craft links in an E-Mail message or calendar invite to execute arbitrary JavaScript. The attack requires an A element containing an href attribute with a "www" substring (including the quotes) followed immediately by a DOM event listener such as onmouseover. This is fixed in 9.0.0 Patch 2.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References