CVE-2024-45510

An issue was discovered in Zimbra Collaboration (ZCS) through 10.0. Zimbra Webmail (Modern UI) is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper sanitization of user input. This allows an attacker to inject malicious code into specific fields of an e-mail message. When the victim adds the attacker to their contacts, the malicious code is stored and executed when viewing the contact list. This can lead to unauthorized actions such as arbitrary mail sending, mailbox exfiltration, profile picture alteration, and other malicious actions. Proper sanitization and escaping of input fields are necessary to mitigate this vulnerability.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
mitreCNA
---
---
CISA-ADPADP
6.1 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 19%
VendorProductVersion
synacorzimbra_collaboration_suite
𝑥
< 9.0.0
synacorzimbra_collaboration_suite
10.0.0 ≤
𝑥
< 10.0.9
synacorzimbra_collaboration_suite
9.0.0
synacorzimbra_collaboration_suite
9.0.0:p1
synacorzimbra_collaboration_suite
9.0.0:p10
synacorzimbra_collaboration_suite
9.0.0:p11
synacorzimbra_collaboration_suite
9.0.0:p12
synacorzimbra_collaboration_suite
9.0.0:p13
synacorzimbra_collaboration_suite
9.0.0:p14
synacorzimbra_collaboration_suite
9.0.0:p15
synacorzimbra_collaboration_suite
9.0.0:p16
synacorzimbra_collaboration_suite
9.0.0:p17
synacorzimbra_collaboration_suite
9.0.0:p18
synacorzimbra_collaboration_suite
9.0.0:p19
synacorzimbra_collaboration_suite
9.0.0:p2
synacorzimbra_collaboration_suite
9.0.0:p20
synacorzimbra_collaboration_suite
9.0.0:p21
synacorzimbra_collaboration_suite
9.0.0:p22
synacorzimbra_collaboration_suite
9.0.0:p23
synacorzimbra_collaboration_suite
9.0.0:p24
synacorzimbra_collaboration_suite
9.0.0:p24.1
synacorzimbra_collaboration_suite
9.0.0:p25
synacorzimbra_collaboration_suite
9.0.0:p26
synacorzimbra_collaboration_suite
9.0.0:p27
synacorzimbra_collaboration_suite
9.0.0:p28
synacorzimbra_collaboration_suite
9.0.0:p29
synacorzimbra_collaboration_suite
9.0.0:p3
synacorzimbra_collaboration_suite
9.0.0:p30
synacorzimbra_collaboration_suite
9.0.0:p31
synacorzimbra_collaboration_suite
9.0.0:p32
synacorzimbra_collaboration_suite
9.0.0:p33
synacorzimbra_collaboration_suite
9.0.0:p34
synacorzimbra_collaboration_suite
9.0.0:p35
synacorzimbra_collaboration_suite
9.0.0:p36
synacorzimbra_collaboration_suite
9.0.0:p37
synacorzimbra_collaboration_suite
9.0.0:p38
synacorzimbra_collaboration_suite
9.0.0:p39
synacorzimbra_collaboration_suite
9.0.0:p4
synacorzimbra_collaboration_suite
9.0.0:p40
synacorzimbra_collaboration_suite
9.0.0:p5
synacorzimbra_collaboration_suite
9.0.0:p6
synacorzimbra_collaboration_suite
9.0.0:p7
synacorzimbra_collaboration_suite
9.0.0:p8
synacorzimbra_collaboration_suite
9.0.0:p9
𝑥
= Vulnerable software versions