S4E just found a medium snmp system information scanner
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-34192 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Zimbra ZCS affects v. 8.8.15.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2023-34192
9.0
CVSScritical
Exploitable remotely over the internet · low-privilege account sufficient · user interaction needed.

Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.

Attack Vector
Network
Privileges Req.
Low
User Interaction
Required
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Zimbra ZCS is an open-source collaboration suite that provides a wide range of tools and functionalities for email, calendaring, task management, and other communication-related tasks. It is widely used by organizations of various sizes and industries, including government agencies, educational institutions, and businesses. 

However, like any other software, Zimbra ZCS is not immune to vulnerabilities that may pose serious threats to its users. One such vulnerability is the CVE-2023-34192, which was detected in version 8.8.15 of the product. This vulnerability enables a remote attacker to execute arbitrary code by leveraging cross-site scripting (XSS) techniques to inject malicious scripts into the /h/autoSaveDraft function, which can result in server-side code execution.

The exploitation of the CVE-2023-34192 vulnerability can have serious consequences, including the theft of sensitive information, system compromise, and unauthorized access to critical resources. It can also lead to the spread of malware throughout the entire network, putting the entire organization at risk.

In conclusion, it is crucial for organizations that rely on Zimbra ZCS to be aware of potential vulnerabilities such as the CVE-2023-34192. By implementing the precautions mentioned above and regularly monitoring their systems, they can protect against potential attacks and minimize the risk of being compromised. Furthermore, with the help of advanced security tools such as s4e.io, users can easily and quickly learn about vulnerabilities in their digital assets and take the necessary actions to ensure their safety.

 

REFERENCES

Solution Advice

To protect against this vulnerability, several precautions can be taken, including:

  • Regularly updating Zimbra ZCS to the latest version and hotfixes
  • Restricting access to the /h/autoSaveDraft function and other critical resources
  • Implementing content security policies (CSP) to prevent XSS attacks
  • Using web application firewalls (WAF) to detect and block malicious requests
  • Conducting regular security audits and penetration testing to identify vulnerabilities and weaknesses.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-34192 scanner - Cross-Site Scripting (XSS) vulnerability in Zimbra ZCS S4E