Junglewise Threat Intelligence

CVE-2023-34192: Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

CVE-2023-34192 · Severity: critical · CVSS 9 · Exploited in the wild · Published 2025-02-25

Technologies: Synacor Zimbra Collaboration Suite (ZCS). Vendors: Synacor.

Executive brief

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the /h/autoSaveDraft function. A remote authenticated attacker can exploit this by sending a crafted script, potentially leading to arbitrary code execution in the context of the user's session.

Affected products

  • Synacor Zimbra Collaboration Suite (ZCS) 8.8.15 up to patch 30

Timeline

  • 2025-02-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-02-25: disclosed

Related threats