Cve20207796 Zimbra Collaboration Suite !link! Full Site

Attackers can reach internal services or administration interfaces that are not exposed to the public internet .

GET /service/home/~/?auth=co&fmt=riched&user=INBOX%22%3E%3Cscript%3E POST /service/proxy?target=https://attacker.com/ Abnormal Calendar invite with HTML payload in DESCRIPTION field cve20207796 zimbra collaboration suite full

Look for the following in Zimbra logs ( /opt/zimbra/log/access_log.nginx* , mailbox.log ): cve20207796 zimbra collaboration suite full

By taking the necessary steps to mitigate the risks associated with CVE-2020-7796, organizations can protect their users and prevent potential cyber threats. cve20207796 zimbra collaboration suite full

: If patching is not immediately possible, disable the WebEx Zimlet or the associated JSP functionality to close the attack vector.