First published: Wed Mar 12 2025(Updated: )
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Reflected Cross-Site Scripting (XSS) vulnerability exists in the /h/rest endpoint, allowing authenticated attackers to inject and execute arbitrary JavaScript in a victim's session. Exploitation requires a valid auth token and involves a crafted URL with manipulated query parameters that triggers XSS when accessed by a victim.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zimbra Collaboration Suite | >=9.0<=10.1 | |
Zimbra Collaboration Suite | >=10.0.0<10.0.11 | |
Zimbra Collaboration Suite | =9.0.0 | |
Zimbra Collaboration Suite | =10.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27914 has a medium severity rating due to its potential for authenticated exploitation through Cross-Site Scripting.
To fix CVE-2025-27914, update Zimbra Collaboration (ZCS) to the latest patched version that resolves this vulnerability.
CVE-2025-27914 affects users of Zimbra Collaboration Suite versions 9.0 to 10.1.
CVE-2025-27914 is a Reflected Cross-Site Scripting (XSS) vulnerability that allows execution of arbitrary JavaScript.
No, exploiting CVE-2025-27914 requires an authenticated session with a valid auth token.