PT-2024-21901 · Zimbra · Zimbra Collaboration

CVE-2024-27443

·

Published

2024-02-28

·

Updated

2026-07-14

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Zimbra Collaboration (ZCS) version 9.0 Zimbra Collaboration (ZCS) version 10.0
Description An issue exists in the CalendarInvite feature of the Zimbra webmail classic user interface due to improper input validation when handling the calendar header. An attacker can exploit this by sending an email containing a crafted calendar header with an embedded Cross-Site Scripting (XSS) payload. When a victim views the message, the payload executes within the victim's session, potentially allowing the execution of arbitrary JavaScript code. Approximately 129,000 servers are affected, and the issue has been exploited in the wild, specifically targeting defense companies and government entities.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-07576
CVE-2024-27443

Affected Products

Zimbra Collaboration