CVE-2024-27443
published 2024-08-12CVE-2024-27443: An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the…
PriorityP278medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2025-06-09
Exploited in the wild
EPSS
23.63%
97.6th percentile
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zimbra | collaboration | — | — |
| zimbra | collaboration | >= 10.0.0 < 10.0.7 | 10.0.7 |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered via the X-Zimbra-Calendar-Intended-For header in calendar invite emails. Monitor for unsanitized JavaScript injection in this header field within inbound email traffic. ↗
- →APT28 (Operation RoundPress) embedded base64-encoded JavaScript payloads in calendar invites. Look for base64-encoded script content within calendar invite emails targeting Zimbra Classic Web Client users. ↗
- →The malicious payload exfiltrates data via HTTP POST requests to hardcoded C2 addresses. Monitor for anomalous outbound HTTP POST requests originating from Zimbra webmail sessions, especially carrying email content, contacts, or session data. ↗
- →The payload creates invisible input fields to harvest autofilled credentials from browser/password managers. Detect DOM manipulation creating hidden input fields within the Zimbra webmail context. ↗
- →Exploitation requires only the victim opening the email — no clicks or redirects needed. Alert on calendar invite emails with script-like content in headers, especially targeting Zimbra 9.0 or 10.0 (pre-10.0.7) deployments. ↗
- →Use the Nuclei template version extractor regex against /js/zimbraMail/share/model/ZmSettings.js to fingerprint vulnerable Zimbra instances (versions 9.0.0 and >= 10.0.0 < 10.0.7).
- →The payload has no persistence — it only executes when the malicious email is opened. Detection must focus on in-session behavior rather than host-based persistence artifacts. ↗
- ·The vulnerability affects Zimbra Collaboration (ZCS) versions 9.0 and 10.0 specifically in the Classic Web Client. Modern/Next-gen UI is not mentioned as affected. ↗
- ·Fixed versions are 8.8.15 P46, 9.0.0 P39, and 10.0.7. Ensure detection/hunting scope covers all three affected branches. ↗
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
vulncheck6.1MEDIUM
cisa6.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
cisa·2025-05-19·CVSS 6.1
CVE-2024-27443 [MEDIUM] CWE-79 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
Vulnerability: Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
Affected: Synacor Zimbra Collaboration Suite (ZCS)
Zimbra Collaboration contains a cross-site scripting (XSS) vulnerability in the CalendarInvite feature of the Zimbra webmail classic user interface. An attacker can exploit this vulnerability via an email message containing a crafted calendar header, leading to the execution of arbitrary JavaScript code.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P46#Security_Fixes ; https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P39#Security_Fixes ; https://
GHSA
GHSA-qrvg-mg33-q843: An issue was discovered in Zimbra Collaboration (ZCS) 9
ghsa_unreviewed·2024-08-12
CVE-2024-27443 [MEDIUM] CWE-79 GHSA-qrvg-mg33-q843: An issue was discovered in Zimbra Collaboration (ZCS) 9
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code.
VulnCheck
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
vulncheck·2024·CVSS 6.1
CVE-2024-27443 [MEDIUM] CWE-79 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
Zimbra Collaboration contains a cross-site scripting (XSS) vulnerability in the CalendarInvite feature of the Zimbra webmail classic user interface. An attacker can exploit this vulnerability via an email message containing a crafted calendar header, leading to the execution of arbitrary JavaScript code.
Affected: Synacor Zimbra Collaboration Suite (ZCS)
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://www.welivesecurity.com/en/eset-research/operation-roundpress/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities
No detection rules found.
Nuclei
Zimbra Collaboration - Cross-Site Scripting (XSS)
nuclei·CVSS 6.1
CVE-2024-27443 [MEDIUM] Zimbra Collaboration - Cross-Site Scripting (XSS)
Zimbra Collaboration - Cross-Site Scripting (XSS)
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload.
Template:
id: CVE-2024-27443
info:
name: Zimbra Collaboration - Cross-Site Scripting (XSS)
author: rxerium
severity: medium
description: |
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input
Hackernews
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
blogs_hackernews·2026-07-11·CVSS 5.4
CVE-2025-27915 [MEDIUM] Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code execution.
The vulnerability has been described as a case of stored cross-site scripting (XSS) that could allow specially crafted emails to execute malicious scripts in a user's session. It has yet to be assigned a CVE identifier.
"The update fixes a security issue in the Classic Web Client where a specially crafted email could run malicious code when the email is opened," Zimbra said . "
Bleepingcomputer
Government webmail hacked via XSS bugs in global spy campaign
blogs_bleepingcomputer·2025-05-15·CVSS 6.1
[MEDIUM] Government webmail hacked via XSS bugs in global spy campaign
## Government webmail hacked via XSS bugs in global spy campaign
## Bill Toulas
Notable targets include governments in Greece, Ukraine, Serbia, and Cameroon, military units in Ukraine and Ecuador, defense companies in Ukraine, Bulgaria, and Romania, and critical infrastructure in Ukraine and Bulgaria.
## Open email, have data stolen
The attack starts with a spear-phishing email referencing current news or political events, often including excerpts from news articles to add legitimacy.
A malicious JavaScript payload embedded in the HTML body of the email triggers the exploitation of a cross-site scripting (XSS) vulnerability in the webmail browser page used by the recipient.
All that is needed from the victim is to open the email to view it, as no other interaction/clicks, redirection
2024-08-12
Published
2025-05-19
Added to CISA KEV
Exploited in the wild