Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Desktop 7.1.2 b10978 allow remote attackers to inject arbitrary web script or HTML via the (1) Username or (2) MailBox Name.
- http://seclists.org/fulldisclosure/2012/Jan/244
- http://www.vulnerability-lab.com/get_content.php?id=378
No PoCs found on GitHub currently.