CVE-2022-24682

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
synacorzimbra_collaboration_suite
8.8.0 ≤
𝑥
< 8.8.15
synacorzimbra_collaboration_suite
8.8.15
synacorzimbra_collaboration_suite
8.8.15:p1
synacorzimbra_collaboration_suite
8.8.15:p10
synacorzimbra_collaboration_suite
8.8.15:p11
synacorzimbra_collaboration_suite
8.8.15:p12
synacorzimbra_collaboration_suite
8.8.15:p13
synacorzimbra_collaboration_suite
8.8.15:p14
synacorzimbra_collaboration_suite
8.8.15:p15
synacorzimbra_collaboration_suite
8.8.15:p16
synacorzimbra_collaboration_suite
8.8.15:p17
synacorzimbra_collaboration_suite
8.8.15:p18
synacorzimbra_collaboration_suite
8.8.15:p19
synacorzimbra_collaboration_suite
8.8.15:p2
synacorzimbra_collaboration_suite
8.8.15:p20
synacorzimbra_collaboration_suite
8.8.15:p21
synacorzimbra_collaboration_suite
8.8.15:p22
synacorzimbra_collaboration_suite
8.8.15:p23
synacorzimbra_collaboration_suite
8.8.15:p24
synacorzimbra_collaboration_suite
8.8.15:p25
synacorzimbra_collaboration_suite
8.8.15:p26
synacorzimbra_collaboration_suite
8.8.15:p27
synacorzimbra_collaboration_suite
8.8.15:p28
synacorzimbra_collaboration_suite
8.8.15:p29
synacorzimbra_collaboration_suite
8.8.15:p3
synacorzimbra_collaboration_suite
8.8.15:p4
synacorzimbra_collaboration_suite
8.8.15:p5
synacorzimbra_collaboration_suite
8.8.15:p6
synacorzimbra_collaboration_suite
8.8.15:p7
synacorzimbra_collaboration_suite
8.8.15:p8
synacorzimbra_collaboration_suite
8.8.15:p9
𝑥
= Vulnerable software versions