Vulnerabilities > Zarafa > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-04-11 CVE-2019-7219 Cross-site Scripting vulnerability in Zarafa Webaccess 7.2.048204
Unauthenticated reflected cross-site scripting (XSS) exists in Zarafa Webapp 2.0.1.47791 and earlier.
network
low complexity
zarafa CWE-79
6.1
2018-03-19 CVE-2014-5450 Information Exposure vulnerability in Zarafa Collaboration Platform 4.1
Zarafa Collaboration Platform 4.1 uses world-readable permissions for /etc/zarafa/license, which allows local users to obtain sensitive information by reading license files.
local
low complexity
zarafa CWE-200
5.5