216.73.217.22

CVE-2021-35207

· Published 02/07/2021 21:15 · Modified 20/12/2025 23:48 · Author: The MITRE Corporation

Labels: CVE-2021-35207

Essential information

Published
02/07/2021 21:15
Modified
20/12/2025 23:48
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
6.1 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/C:L/I:L/A:N

CVSS metrics

Description

An issue was discovered in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.0 before 9.0.0 Patch 16. An XSS vulnerability exists in the login component of Zimbra Web Client, in which an attacker can execute arbitrary JavaScript by adding executable JavaScript to the loginErrorCode parameter of the login url.

NVD status

NVD
View on NVD