.. / CVE-2022-27926

Exploit for Zimbra Collaboration (ZCS) - Cross Site Scripting (CVE-2022-27926)

Description:

A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated attackers to execute arbitrary web script or HTML via request parameters.

Nuclei Template

View the template here CVE-2022-27926.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-27926.yaml
Copy

References:

https://github.com/ARPSyndicate/cvemon
https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P24
https://nvd.nist.gov/vuln/detail/CVE-2022-27926
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
https://wiki.zimbra.com/wiki/Security_Center