cvedb.io
CVE-2022-45911
MEDIUM · CVSS 6.1
EPSS exploitation probability: 0%
Published 2023-01-06T23:15:09.673 · Last modified 2026-06-17T05:10:58.770

Summary

An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur on the Classic UI login page by injecting arbitrary JavaScript code in the username field. This occurs before the user logs into the system, which means that even if the attacker executes arbitrary JavaScript, they will not get any sensitive information.

Affected products

zimbra — collaboration

Does this affect you?

Add your gear to cvedb and we'll alert you only when zimbra ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.