CyberRota Analysis
AI-GeneratedThe Zimbra Collaboration Suite prior to version 10.1.17 is vulnerable to a stored cross-site scripting (XSS) flaw in the Classic Web Client, stemming from inadequate sanitization of attachment content during inline previews. This vulnerability allows attackers to execute arbitrary JavaScript in the victim's browser, potentially enabling unauthorized actions and data exfiltration. Organizations using affected versions of Zimbra should prioritize patching to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a crafted email containing a malicious attachment that, when previewed by a user, executes arbitrary JavaScript within the victim's browser session. Successful exploitation may allow an attacker to perform unauthorized actions on behalf of the victim user, potentially leading to data exfiltration or unauthorized access to sensitive information.