CVE Tools
Back to feed
Patch released Classic Web Client web-app Zimbra

Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions

The Hacker News·By The Hacker News··2 min read
CVE Tools coverage

Zimbra has issued a security update to resolve a critical vulnerability in the Classic Web Client that could enable arbitrary code execution through specially crafted emails. The flaw, classified as a stored cross-site scripting (XSS) issue, allows attackers to inject and execute malicious scripts within a user’s session upon opening an affected email. Though no exploitation has been reported so far, past XSS vulnerabilities in Zimbra have drawn significant interest from threat actors. Users are strongly advised to upgrade to Zimbra Collaboration Suite version 10.1.19 to mitigate this risk.