Zimbra urges customers to patch critical web client XSS flaw
Customers were asked by the Zimbra security team to fix a serious flaw in the Classic Web Client, which is used to access the Zimbra Collaboration suite.
Hundreds of millions of individuals, including thousands of organizations and hundreds of government bodies worldwide, utilize the highly popular email and collaboration software suite Zimbra. This Ajax-based webmail interface, also referred to as the Classic UI, loads huge email folders more quickly than Zimbra's contemporary web client.
In order to address this stored cross-site scripting (XSS) security vulnerability, which has not yet been assigned a CVE ID for simple tracking, the business published Zimbra 10.1.19 on Tuesday. Attackers can exploit this Classic Web Client security flaw with specially prepared emails that execute...

