Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
PatchClassic Web ClientOur summary
Zimbra has issued a security update to resolve a critical vulnerability in the Classic Web Client that could enable arbitrary code execution through specially crafted emails. The flaw, classified as a stored cross-site scripting (XSS) issue, allows attackers to inject and execute malicious scripts within a user’s session upon opening an affected email. Though no exploitation has been reported so far, past XSS vulnerabilities in Zimbra have drawn significant interest from threat actors. Users are strongly advised to upgrade to Zimbra Collaboration Suite version 10.1.19 to mitigate this risk.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.