Executive brief
Synacor Zimbra Collaboration Suite, a widely used enterprise email and collaboration platform, contains a security flaw in its 'Classic' web interface. An attacker can send a specially crafted email that, when viewed by a user, executes malicious code in their browser. This could allow the attacker to steal sensitive information, access the user's mailbox, or perform actions on the user's behalf without their knowledge.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in the Zimbra Classic UI due to insufficient sanitization of HTML content in email messages. The flaw is specifically triggered by crafted tag structures and attribute values containing '@import' directives or other script injection vectors. An unauthenticated remote attacker can exploit this by sending a malicious email to a target user; the payload executes automatically when the victim views the message. This can lead to session hijacking or unauthorized access to sensitive user data. The vulnerability has been observed in active exploitation and affects versions 8.8.15, 9.0, 10.0, and 10.1.
Affected products
- Synacor Zimbra Collaboration Suite (ZCS) 8.8.15, 9.0, 10.0, 10.1
Timeline
- 2025-07-11: disclosed: Initial discovery and analysis by NIST
- 2026-04-20: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2026-04-20: advisory: Public advisory published