Executive brief
Zimbra Collaboration Suite is a widely used enterprise email and collaboration platform. A security flaw in its classic webmail interface allows an attacker to execute malicious code in a user's browser simply by sending them a specially crafted calendar invitation. This could allow an attacker to steal session information, access sensitive emails, or perform actions on behalf of the victim. This vulnerability has been observed being used in active attacks.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface (CWE-79). The issue stems from improper input validation of calendar headers in incoming email messages. An unauthenticated remote attacker can exploit this by sending an email with a malicious payload embedded in the calendar header; when a victim views the message, the payload executes in the context of their session. This vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Patches are available in Zimbra 9.0.0 Patch 39 and Zimbra 10.0.7.
Affected products
- Synacor Zimbra Collaboration Suite (ZCS) 9.0.0 before P39, 10.0.0 before 10.0.7
Timeline
- 2024-03-17: advisory: Initial CVSS scoring and CWE assignment
- 2025-05-19: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2025-05-19: exploited: Confirmed active exploitation in the wild