CyberRota Analysis
AI-GeneratedAn unauthenticated attacker can exploit a stored cross-site scripting (XSS) vulnerability in Zimbra Modern by forging a share notification, which, when accepted by a signed-in user, allows the attacker to access the victim's mailbox data and perform actions on their behalf. This critical vulnerability poses a significant risk to organizations using Zimbra, particularly those handling sensitive information. Administrators should prioritize patching this issue to mitigate potential data breaches and unauthorized access.
Original NVD Description
An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.