Zimbra XSS (show fragment / snippet) - Zimlet Hotfix

Discuss your pilot or production implementation with other Zimbra admins or our engineers.
Post Reply
ozzi
Posts: 7
Joined: Mon Nov 13, 2017 12:23 pm

Zimbra XSS (show fragment / snippet) - Zimlet Hotfix

Post by ozzi »

Hi there

I developed this small Zimlet which disables the vulnerable show snippet (in the code its called a fragment) functionality.
Tested with Zimbra 8.7.

https://github.com/ozzi-/Zimbra-CVE-2017-8802-Hotifx

Regards
Post Reply