The open source, enterprise email software Zimbra was recently updated to version 10.1.19, and parent company Synacor urged users to update as soon as possible. Specifically, the update addresses a vulnerability in the Classic Web Client, where malicious emails could execute arbitrary code when opened due to a cross-site scripting (XSS) exploit, compromising the security of the account and machine.
Source: HotHardware
