[Users] Another XSS issue

David Touitou david at network-studio.com
Fri Jan 12 10:44:13 CET 2018


Hello all,

I got a mail in the bugtraq mailing list about another XSS discovered.
And fixed for 8.8+ versions of ZCS.

However, nothing for 8.6.
Nothing for that XSS and all the XSS discovered since 2016.
https://forums.zimbra.org/viewtopic.php?f=13&t=63390

Does anyone here know if all these XSS are only issues with 8.7+ code base?
Or did they (synacor) just "forgot" to provide patch for 8.6?

Best,
David




More information about the Users mailing list