No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Zimbra Zero-Day Demands Urgent Manual Update

July 15, 2023
in Protection
0
Zimbra Zero-Day Demands Urgent Manual Update



Teams running the Zimbra Collaboration Suite version 8.8.15 are urged to apply a manual fix against a recently discovered zero-day vulnerability that’s being actively exploited in the wild.

The Zimbra cloud suite offers email, calendar functions, and other enterprise collaboration tools. The vulnerability compromises the security of data on Zimbra servers, the company said in its security advisory.

“A security vulnerability in Zimbra Collaboration Suite Version 8.8.15 that could potentially impact the confidentiality and integrity of your data has surfaced,” the company said. “We take this matter very seriously and have already taken immediate action to address the issue.”

The reflected cross-site scripting (XSS) vulnerability was discovered by Google Threat Analysis Group (TAG) researcher Clément Lecigne. Fellow TAG researcher Maddie Stone confirmed the Zimbra zero-day is being targeted in the wild in a July 13 tweet. 

No Automatic Patch Yet

Although Zimbra has a fix, it won’t roll out automatically until its scheduled July update, which is why the company is asking customers to manually apply a fix to all mailbox nodes.

The company urges its users take the following steps:

  1. Take a backup of the file /opt/zimbra/jetty/webapps/zimbra/m/momoveto
  2. Edit this file and go to line number 40
  3. Update the parameter value as below
    <input name=”st” type=”hidden” value=”$fn:escapeXml(param.st)”/>
  4. Before the update, the line appeared as below
    <input name=”st” type=”hidden” value=”$param.st”/>
  5. After the update, the line should appear as below:
    <input name=”st” type=”hidden” value=”$fn:escapeXml(param.st)”/>

Zimbra added in its security advisory that a service restart is not required. 

Zimbra: A Popular Cybercriminal Target

The risk for not patching is real: Zimbra products are popular among advanced persistent threat (APT) and other cyber-threat groups. Earlier this year, the North Korean government was discovered using a Zimbra zero-day vulnerability to spy on a collection of medical and energy sector organizations. Months earlier, in late 2022, threat actors were discovered actively exploiting a a remote code execution vulnerability in Zimbra email servers.

Last November, the Cybersecurity and Infrastructure Security Agency (CISA) issued a blanket warning that if enterprises were running Zimbra collaboration suites, they should assume they have been compromised.

Keep up with the latest cybersecurity threats, newly-discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

Subscribe



Editorial Team

Editorial Team

Related Posts

Samsung Says the Memory Crisis Will Get Worse, so You Have Two Choices
Protection

Samsung Says the Memory Crisis Will Get Worse, so You Have Two Choices

April 30, 2026
Amazon Prime Day Is Coming Early This Year
Protection

Amazon Prime Day Is Coming Early This Year

April 30, 2026
The Samsung Odyssey OLED G9 Is $300 Off
Protection

The Samsung Odyssey OLED G9 Is $300 Off

April 30, 2026
No, Sony Isn't Forcing Gamers to Connect to the Internet Every 30 Days
Protection

No, Sony Isn’t Forcing Gamers to Connect to the Internet Every 30 Days

April 30, 2026
15 Shows Like 'Nobody Wants This' You Should Watch Next
Protection

15 Shows Like ‘Nobody Wants This’ You Should Watch Next

April 30, 2026
The Anker Prime 3-in-1 MagSafe Charger Is 35% Off Right Now
Protection

The Anker Prime 3-in-1 MagSafe Charger Is 35% Off Right Now

April 30, 2026
Load More
Next Post
Defence secretary Ben Wallace to quit Westminster

Defence secretary Ben Wallace to quit Westminster

Popular News

  • 35 Best Hotels in New York City We Won't Shut Up About

    35 Best Hotels in New York City We Won’t Shut Up About

    0 shares
    Share 0 Tweet 0
  • ZTX partners with ZGM to offer game prediction competition and prizes

    0 shares
    Share 0 Tweet 0
  • Bitcoin Will Not Crash, But Rise In A Recession: Expert

    0 shares
    Share 0 Tweet 0
  • AIM Summit London Edition 2026 

    0 shares
    Share 0 Tweet 0
  • ‘I hope to retire early’: I’m 56 and have 80% in a traditional IRA and 20% in a Roth. Am I in trouble?

    0 shares
    Share 0 Tweet 0

Latest News

Official Trump price prediction: Is TRUMP headed for a major drop or a surprise rebound?

Trump orders Iran briefing as crypto falls

April 30, 2026
0

President Trump will receive a military briefing today from CENTCOM Commander Admiral Brad Cooper on new Iran options, including a...

US railroads Union Pacific, Norfolk Southern seek approval for $85 billion merger

US railroads Union Pacific, Norfolk Southern seek approval for $85 billion merger

April 30, 2026
0

US railroads Union Pacific, Norfolk Southern seek approval for $85 billion merger

Geopolitical tensions, SPR releases fail to sway oil $90 prediction by June

Geopolitical tensions, SPR releases fail to sway oil $90 prediction by June

April 30, 2026
0

## Market Snapshot The “Crude Oil Price Predictions by June” market currently reflects a 100% YES pricing for oil hitting...

Stocks making the biggest moves after hours: AAPL, RBLX, RDDT, ROKU

Stocks making the biggest moves after hours: AAPL, RBLX, RDDT, ROKU

April 30, 2026
0

Check out the companies making headlines after the bell : Apple — Shares were up 2%. For the fiscal second...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.