Patch released Zimbra Collaboration Suite web-app Zimbra
Zimbra urges customers to patch critical web client XSS flaw
CVE Tools coverage
Zimbra has issued an urgent update for a critical cross-site scripting (XSS) vulnerability impacting the Classic Web Client of its widely used Zimbra Collaboration Suite. The flaw, which allows attackers to inject malicious scripts via specially crafted emails, remains unassigned a CVE ID but is now patched in version 10.1.19. While there is no evidence of active exploitation at this time, the vulnerability was reported by Google’s Threat Analysis Group, known for uncovering sophisticated cyber threats. Zimbra strongly advises all users of the Classic Web Client to upgrade immediately to prevent potential theft of session data and mailbox information.