CVE-2022-27926
KEVlargeReflected XSS in Synacor Zimbra Collaboration Suite 9.0 (launchNewWindow.jsp)
CISA: Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
CVE-2022-27926 is a reflected cross-site scripting (CWE-79) flaw in the /public/launchNewWindow.jsp component of Zimbra Collaboration Suite (ZCS) 9.0. An unauthenticated attacker can craft a request to this page whose parameters are reflected into the rendered page, so arbitrary web script or HTML executes in the victim's browser when the user visits the attacker-supplied link (consistent with the CVSS user-interaction requirement). Successful exploitation lets the attacker run script in the context of the user's webmail session — for example to steal cookies or credentials, issue further requests against the server, or display attacker-controlled content — with limited-to-low confidentiality and integrity impact and no availability impact. Any organization running unpatched ZCS 9.0, particularly self-hosted, internet-exposed webmail servers used by enterprises and government entities, is affected. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-04-03, and reporting ties Zimbra exploitation to the Winter Vivern APT's targeting of European government and NATO-country email portals; EPSS assigns a 17.6% probability of exploitation within 30 days.
What to do: Apply the current ZCS 9.0 patch/updates from the vendor per Synacor/Zimbra's instructions, as this is the required action in CISA's KEV catalog, prioritizing internet-exposed webmail servers. Review web logs for requests to /public/launchNewWindow.jsp containing unexpected script or HTML in request parameters, and consider restricting access to /public/ if it is not required. Because exploitation requires user interaction, warn users about suspicious webmail links while patching is completed.
| Synacor Zimbra Collaboration Suite (ZCS) | 9.0 (per the CVE description; apply current vendor patches) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated attackers to execute arbitrary web script or HTML via request parameters.
- Affected
- Synacor Zimbra Collaboration Suite (ZCS)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- synacor
- Products
- zimbra collaboration suite
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N