{"id":"CVE-2020-18984","details":"A reflected cross-site scripting (XSS) vulnerability in the zimbraAdmin/public/secureRequest.jsp component of Zimbra Collaboration 8.8.12 allows unauthenticated attackers to execute arbitrary web scripts or HTML via a host header injection.","modified":"2026-07-08T16:27:30.183508Z","published":"2021-12-15T23:15:08.693Z","references":[{"type":"REPORT","url":"https://github.com/buxu/bug/issues/2"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zimbra/zm-build","events":[{"introduced":"a3f5dae50fd9c34d9802c5fb2783dd130a600eff"},{"last_affected":"a3f5dae50fd9c34d9802c5fb2783dd130a600eff"}],"database_specific":{"cpe":"cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.12:-:*:*:*:*:*:*","extracted_events":[{"introduced":"8.8.12-NA"},{"last_affected":"8.8.12-NA"}],"source":"CPE_STRING"}}],"versions":["8.8.12-NA","8.8.12"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-18984.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/zimbra/zm-mailbox","events":[{"introduced":"85d81f636d6cb4ce5a66ac5823494ecb78f84b95"},{"last_affected":"85d81f636d6cb4ce5a66ac5823494ecb78f84b95"}],"database_specific":{"extracted_events":[{"introduced":"8.8.12-NA"},{"last_affected":"8.8.12-NA"}],"source":"CPE_STRING","cpe":"cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.12:-:*:*:*:*:*:*"}}],"versions":["8.8.12-NA","8.8.12"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-18984.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/zimbra/zm-zcs","events":[{"introduced":"aa13056509ffbbf7434066e6280b0f0208307268"},{"last_affected":"aa13056509ffbbf7434066e6280b0f0208307268"}],"database_specific":{"cpe":"cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.12:-:*:*:*:*:*:*","extracted_events":[{"introduced":"8.8.12-NA"},{"last_affected":"8.8.12-NA"}],"source":"CPE_STRING"}}],"versions":["8.8.12-NA","8.8.12"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-18984.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/zimbra/zm-zcs-lib","events":[{"introduced":"8fc797a26d4b5bc40b8d3fc124c89e30e20a8790"},{"last_affected":"8fc797a26d4b5bc40b8d3fc124c89e30e20a8790"}],"database_specific":{"cpe":"cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.12:-:*:*:*:*:*:*","extracted_events":[{"introduced":"8.8.12-NA"},{"last_affected":"8.8.12-NA"}],"source":"CPE_STRING"}}],"versions":["8.8.12-NA","8.8.12"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-18984.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}