An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur on the Classic UI login page by injecting arbitrary JavaScript code in the username field. This occurs before the user logs into the system, which means that even if the attacker executes arbitrary JavaScript, they will not get any sensitive information.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | epss 
 | epss 
 | 
Wed, 09 Apr 2025 21:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published: 2023-01-06T00:00:00.000Z
Updated: 2025-04-09T20:31:37.345Z
Reserved: 2022-11-26T00:00:00.000Z
Link: CVE-2022-45911
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-03T14:24:03.221Z
 NVD
                        NVD
                    Status : Modified
Published: 2023-01-06T23:15:09.673
Modified: 2025-04-09T21:15:42.780
Link: CVE-2022-45911
 Redhat
                        Redhat
                    No data.