CVE-2025-27914: XSS
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Reflected Cross-Site Scripting (XSS) vulnerability exists in the /h/rest endpoint, allowing authenticated attackers to inject and execute arbitrary JavaScript in a victim's session. Exploitation requires a valid auth token and involves a crafted URL with manipulated query parameters that triggers XSS when accessed by a victim.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27914?
CVE-2025-27914 has a medium severity rating due to its potential for authenticated exploitation through Cross-Site Scripting.
How do I fix CVE-2025-27914?
To fix CVE-2025-27914, update Zimbra Collaboration (ZCS) to the latest patched version that resolves this vulnerability.
Who is affected by CVE-2025-27914?
CVE-2025-27914 affects users of Zimbra Collaboration Suite versions 9.0 to 10.1.
What type of vulnerability is CVE-2025-27914?
CVE-2025-27914 is a Reflected Cross-Site Scripting (XSS) vulnerability that allows execution of arbitrary JavaScript.
Can CVE-2025-27914 be exploited without authentication?
No, exploiting CVE-2025-27914 requires an authenticated session with a valid auth token.