First published: Wed Mar 12 2025(Updated: )
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an e-mail message containing a malicious ICS entry, its embedded JavaScript executes via an ontoggle event inside a <details> tag. This allows an attacker to run arbitrary JavaScript within the victim's session, potentially leading to unauthorized actions such as setting e-mail filters to redirect messages to an attacker-controlled address. As a result, an attacker can perform unauthorized actions on the victim's account, including e-mail redirection and data exfiltration.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zimbra Collaboration Suite | >=9.0<=10.1 | |
Zimbra Collaboration Suite | >=10.0.0<10.0.13 | |
Zimbra Collaboration Suite | >=10.1.0<10.1.5 | |
Zimbra Collaboration Suite | =9.0.0 | |
Zimbra Collaboration Suite | =9.0.0-p0 | |
Zimbra Collaboration Suite | =9.0.0-p1 | |
Zimbra Collaboration Suite | =9.0.0-p10 | |
Zimbra Collaboration Suite | =9.0.0-p11 | |
Zimbra Collaboration Suite | =9.0.0-p12 | |
Zimbra Collaboration Suite | =9.0.0-p13 | |
Zimbra Collaboration Suite | =9.0.0-p14 | |
Zimbra Collaboration Suite | =9.0.0-p15 | |
Zimbra Collaboration Suite | =9.0.0-p16 | |
Zimbra Collaboration Suite | =9.0.0-p19 | |
Zimbra Collaboration Suite | =9.0.0-p2 | |
Zimbra Collaboration Suite | =9.0.0-p20 | |
Zimbra Collaboration Suite | =9.0.0-p21 | |
Zimbra Collaboration Suite | =9.0.0-p23 | |
Zimbra Collaboration Suite | =9.0.0-p24 | |
Zimbra Collaboration Suite | =9.0.0-p24.1 | |
Zimbra Collaboration Suite | =9.0.0-p25 | |
Zimbra Collaboration Suite | =9.0.0-p26 | |
Zimbra Collaboration Suite | =9.0.0-p27 | |
Zimbra Collaboration Suite | =9.0.0-p28 | |
Zimbra Collaboration Suite | =9.0.0-p29 | |
Zimbra Collaboration Suite | =9.0.0-p3 | |
Zimbra Collaboration Suite | =9.0.0-p30 | |
Zimbra Collaboration Suite | =9.0.0-p31 | |
Zimbra Collaboration Suite | =9.0.0-p32 | |
Zimbra Collaboration Suite | =9.0.0-p33 | |
Zimbra Collaboration Suite | =9.0.0-p34 | |
Zimbra Collaboration Suite | =9.0.0-p35 | |
Zimbra Collaboration Suite | =9.0.0-p36 | |
Zimbra Collaboration Suite | =9.0.0-p37 | |
Zimbra Collaboration Suite | =9.0.0-p38 | |
Zimbra Collaboration Suite | =9.0.0-p39 | |
Zimbra Collaboration Suite | =9.0.0-p4 | |
Zimbra Collaboration Suite | =9.0.0-p40 | |
Zimbra Collaboration Suite | =9.0.0-p41 | |
Zimbra Collaboration Suite | =9.0.0-p42 | |
Zimbra Collaboration Suite | =9.0.0-p43 | |
Zimbra Collaboration Suite | =9.0.0-p5 | |
Zimbra Collaboration Suite | =9.0.0-p6 | |
Zimbra Collaboration Suite | =9.0.0-p7 | |
Zimbra Collaboration Suite | =9.0.0-p7.1 | |
Zimbra Collaboration Suite | =9.0.0-p8 | |
Zimbra Collaboration Suite | =9.0.0-p9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27915 has been classified as a medium severity vulnerability due to its potential impact on user data through stored cross-site scripting.
To mitigate CVE-2025-27915, users are advised to update to Zimbra Collaboration version 10.1.5 or later.
CVE-2025-27915 affects Zimbra Collaboration versions 9.0 to 10.1.
CVE-2025-27915 is a stored cross-site scripting (XSS) vulnerability.
The risks associated with CVE-2025-27915 include unauthorized access to user sessions and potential data theft.