Executive brief
A cross-site scripting (XSS) vulnerability in the Calendar feature of Zimbra Collaboration Suite allows attackers to inject arbitrary HTML and executable JavaScript via element attributes. This occurs because markup becomes unescaped, leading to arbitrary code execution in the context of the user's session.
Affected products
- Synacor Zimbra Collaboration Suite (ZCS) 8.8.x before 8.8.15 patch 30 (update 1)
Timeline
- 2021-12: exploited: Exploitation in the wild started in December 2021.
- 2022-02-05: patched: Hotfix available for zero-day exploit.
- 2022-02-25: disclosed: Published to NVD.
- 2022-02-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.