CVE-2022-27926 | Synacor Zimbra 9.0 Request Parameter launchNewWindow.jsp cross site scripting
A vulnerability was found in Synacor Zimbra 9.0. It has been declared as problematic. This vulnerability affects unknown code of the file /public/launchNewWindow.jsp of the component Request Parameter Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2022-27926. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.