Zimbra Collaboration before 8.8.12 Patch 1 has persistent XSS.
zimbra_collaboration_server
Vendor: zimbra
Security Vulnerability Index
Page 1 / 1Synacor Zimbra Collaboration before 8.0.9 allows plaintext command injection during STARTTLS.
Synacor Zimbra Collaboration Server 8.x before 8.7.0 has Reflected XSS in admin console.
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) before 8.5 allow remote attackers to hijack the authentication of arbitrary users for requests that change account preferences via a SOAP request to service/soap/BatchRequest.