CVE-2022-24682: Zimbra Webmail Cross-Site Scripting Vulnerability
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.
Other sources
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker to execute arbitrary code.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zimbra Collaboration Suiteto a version that resolves this vulnerability.Fixed in 8.8.15 patch 30 (update 1)
Event History
Frequently Asked Questions
What is CVE-2022-24682?
CVE-2022-24682 is a Cross-Site Scripting vulnerability in Zimbra Webmail.
How does CVE-2022-24682 affect Zimbra Collaboration Suite?
CVE-2022-24682 affects Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1).
How can an attacker exploit CVE-2022-24682?
An attacker can place HTML containing executable JavaScript inside element attributes to exploit CVE-2022-24682.
What is the severity of CVE-2022-24682?
CVE-2022-24682 has a severity level of 6.1 (Medium).
How can I fix CVE-2022-24682?
To fix CVE-2022-24682, update Zimbra Collaboration Suite to version 8.8.15 patch 30 (update 1) or later.