CyberRota Analysis
AI-GeneratedAn unauthenticated calendar sender can exploit a vulnerability in Zimbra Classic by injecting active markup into a COUNTER message's RFC From address, leading to stored cross-site scripting (XSS). This allows attackers to access mailbox data and perform actions on behalf of the victim. Organizations using Zimbra Classic should prioritize patching this critical vulnerability to protect against potential data breaches and unauthorized access.
Original NVD Description
An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.