PT-2023-4007 · Zimbra · Zimbra Collaboration
CVE-2023-37580
·
Published
2023-07-17
·
Updated
2026-07-14
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Zimbra Collaboration (ZCS) versions prior to 8.8.15 Patch 41
Description
Cross-Site Scripting (XSS) exists in the Zimbra Classic Web Client due to the failure of the
autoSaveDraft() function to properly neutralize special elements. A remote attacker can exploit this by tricking a user into clicking a specially crafted URL, allowing the execution of malicious scripts in the victim's web browser. This issue has been exploited in the wild by at least four different threat groups targeting government organizations in Greece, Moldova, Tunisia, Vietnam, and Pakistan to steal email data, user credentials, and authentication tokens.Recommendations
Update Zimbra Collaboration (ZCS) to version 8.8.15 Patch 41 or later.
Exploit
Fix
DoS
Special Elements Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zimbra Collaboration