CVE-2025-66376: Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CSS) @import directives in email HTML.
Other sources
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Synacor Zimbra Collaboration Suite (ZCS) Classic UIto a version that resolves this vulnerability.Fixed in 10.0.18 - Upgrade
Upgrade
Synacor Zimbra Collaboration Suite (ZCS) Classic UIto a version that resolves this vulnerability.Fixed in 10.1.13
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66376?
CVE-2025-66376 is classified as a moderate severity vulnerability due to its potential for stored XSS attacks.
How do I fix CVE-2025-66376?
To mitigate CVE-2025-66376, upgrade Zimbra Collaboration (ZCS) to version 10.0.18 or 10.1.13 or later.
What types of attacks does CVE-2025-66376 enable?
CVE-2025-66376 allows attackers to execute stored cross-site scripting (XSS) attacks through manipulated HTML email messages.
Which versions of Zimbra are affected by CVE-2025-66376?
Zimbra Collaboration (ZCS) versions before 10.0.18 and 10.1 before 10.1.13 are affected by CVE-2025-66376.
Is there a known exploit for CVE-2025-66376?
As of now, there are no publicly disclosed exploits specifically targeting CVE-2025-66376.