Zimbra patched a flaw that let hackers hijack accounts just by sending an email
… Zimbra "Daffodil" 10.1.19 includes a fix for a stored cross-site scripting XSS vulnerability that could be exploited to compromise customers' machines through Zimbra's Classic Web Client.Read Entire Article