peter bassill · operator
$ cve CVE-2024-27443 JSON

CVE-2024-27443 KEV

6.1
MEDIUM · CVSS 3.1 · EPSS 23.6% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2025-06-09.

Description

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code.

Scoring

CVSS6.1 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS23.63% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-79
On CISA KEVyes — remediate by 2025-06-09
Public exploitnone known
Published2024-08-12
Last modified2026-06-17

CISA KEV

NameSynacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
Added2025-05-19
Due2025-06-09
Vendor / productSynacor / Zimbra Collaboration Suite (ZCS)
Ransomware usenone reported

Affected (1)

VendorProduct
zimbracollaboration

References

→ the Explorer  ·  watch your stack  ·  NVD