Executive brief
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the /h/autoSaveDraft function. A remote authenticated attacker can exploit this by sending a crafted script, potentially leading to arbitrary code execution in the context of the user's session.
Affected products
- Synacor Zimbra Collaboration Suite (ZCS) 8.8.15 up to patch 30
Timeline
- 2025-02-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-02-25: disclosed