AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-45514

MEDIUM · CVSS 5.4 EPSS 0.65%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-11-21 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.4. It affects Java.

CVE
CVE-2024-45514
Severity
MEDIUM
CVSS
5.4
EPSS
0.65%
Java

Original NVD Description

An issue was discovered in Zimbra Collaboration (ZCS) through v10.1. A Cross-Site Scripting (XSS) vulnerability exists in one of the endpoints of Zimbra Webmail due to insufficient sanitization of the packages parameter. Attackers can bypass the existing checks by using encoded characters, allowing the injection and execution of arbitrary JavaScript within a victim's session.

Related CVEs

Other vulnerabilities affecting the same vendor(s)