Zimbra Addresses Critical SNMP Command Injection and Multiple XSS Vulnerabilities in Version 10.1.20
Zimbra released patches for critical SNMP command injection and four XSS vulnerabilities in version 10.1.20, addressing issues that could enable arbitrary code execution and unauthorized data exfiltration. The updates include fixes for flaws in the SNMP monitoring component and Classic Web Client, emphasizing the need for immediate application to prevent potential exploitation.
Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component.
As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled.
Also patched
*** END OF TRANSMISSION ***