CVE-2025-27915: Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an e-mail message containing a malicious ICS entry, its embedded JavaScript executes via an ontoggle event inside a <details> tag. This allows an attacker to run arbitrary JavaScript within the victim's session, potentially leading to unauthorized actions such as setting e-mail filters to redirect messages to an attacker-controlled address. As a result, an attacker can perform unauthorized actions on the victim's account, including e-mail redirection and data exfiltration.
Other sources
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an e-mail message containing a malicious ICS entry, its embedded JavaScript executes via an ontoggle event inside a tag. This allows an attacker to run arbitrary JavaScript within the victim's session, potentially leading to unauthorized actions such as setting e-mail filters to redirect messages to an attacker-controlled address. As a result, an attacker can perform unauthorized actions on the victim's account, including e-mail redirection and data exfiltration.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Apply mitigations per vendor instructions for the Synacor Zimbra Collaboration Suite (ZCS) Classic Web Client stored XSS issue involving insufficient sanitization of HTML content in ICS files, or discontinue use of the product if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27915?
CVE-2025-27915 has been classified as a medium severity vulnerability due to its potential impact on user data through stored cross-site scripting.
How do I fix CVE-2025-27915?
To mitigate CVE-2025-27915, users are advised to update to Zimbra Collaboration version 10.1.5 or later.
What versions of Zimbra Collaboration are affected by CVE-2025-27915?
CVE-2025-27915 affects Zimbra Collaboration versions 9.0 to 10.1.
What type of vulnerability is CVE-2025-27915?
CVE-2025-27915 is a stored cross-site scripting (XSS) vulnerability.
What are the potential risks associated with CVE-2025-27915?
The risks associated with CVE-2025-27915 include unauthorized access to user sessions and potential data theft.