PT-2023-4007 · Zimbra · Zimbra Collaboration

CVE-2023-37580

·

Published

2023-07-17

·

Updated

2026-07-14

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zimbra Collaboration (ZCS) versions prior to 8.8.15 Patch 41
Description Cross-Site Scripting (XSS) exists in the Zimbra Classic Web Client due to the failure of the autoSaveDraft() function to properly neutralize special elements. A remote attacker can exploit this by tricking a user into clicking a specially crafted URL, allowing the execution of malicious scripts in the victim's web browser. This issue has been exploited in the wild by at least four different threat groups targeting government organizations in Greece, Moldova, Tunisia, Vietnam, and Pakistan to steal email data, user credentials, and authentication tokens.
Recommendations Update Zimbra Collaboration (ZCS) to version 8.8.15 Patch 41 or later.

Exploit

Fix

DoS

Special Elements Injection

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-04305
CVE-2023-37580

Affected Products

Zimbra Collaboration