Junglewise Threat Intelligence

CVE-2025-27915: Synacor Zimbra Collaboration Suite XSS in Classic Web Client

CVE-2025-27915 · Severity: critical · CVSS 5.4 · Exploited in the wild · Published 2025-10-07

Executive brief

Zimbra Collaboration Suite is a widely used enterprise email and collaboration platform. A security vulnerability in its web interface allows attackers to execute malicious code when a user views a specially crafted calendar (ICS) file. This could allow an attacker to hijack user sessions, steal sensitive emails, or redirect incoming messages to an external address without the user's knowledge.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Zimbra Collaboration Suite (ZCS) Classic Web Client. The root cause is insufficient sanitization of HTML content within uploaded or received ICS (calendar) files. Specifically, malicious JavaScript can be embedded using an 'ontoggle' event handler within a <details> tag. When a victim views an email containing the malicious ICS entry, the script executes in the context of their active session. This allows an attacker to perform actions on behalf of the user, such as modifying email filters to exfiltrate data. This vulnerability has been observed being exploited in the wild.

Affected products

  • Synacor Zimbra Collaboration Suite (ZCS) 9.0, 10.0, 10.1

Timeline

  • 2025-10-07: disclosed
  • 2025-10-07: kev added: Added to CISA Known Exploited Vulnerabilities catalog.

Related threats