PT-2024-21901 · Zimbra · Zimbra Collaboration
CVE-2024-27443
·
Published
2024-02-28
·
Updated
2026-07-14
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Zimbra Collaboration (ZCS) version 9.0
Zimbra Collaboration (ZCS) version 10.0
Description
An issue exists in the CalendarInvite feature of the Zimbra webmail classic user interface due to improper input validation when handling the calendar header. An attacker can exploit this by sending an email containing a crafted calendar header with an embedded Cross-Site Scripting (XSS) payload. When a victim views the message, the payload executes within the victim's session, potentially allowing the execution of arbitrary JavaScript code. Approximately 129,000 servers are affected, and the issue has been exploited in the wild, specifically targeting defense companies and government entities.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zimbra Collaboration