CVE-2023-34192
KEVlarge1Authenticated XSS in Synacor Zimbra Collaboration Suite 8.8.15 Exploited in the Wild
CISA: Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
CVE-2023-34192 is a critical (CVSS 3.1: 9.0) cross-site scripting (CWE-79) flaw in Synacor Zimbra Collaboration Suite (ZCS) 8.8.15. A remote, authenticated attacker submits a crafted script through the /h/autoSaveDraft endpoint (the autosave-draft handler of the web client), and because the vulnerability requires user interaction and changes scope, the script can execute in another user's browser session. By running code/actions in the security context of the victim's session, the attacker gains high-impact access to confidentiality, integrity, and availability (C:H/I:H/A:H per the CVSS vector). Organizations running ZCS 8.8.15 are affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-02-25 amid reported active exploitation, and EPSS is at 77.3% (100th percentile), though no public proof-of-concept is known.
What to do: Upgrade ZCS 8.8.15 deployments to the latest available patch release per Synacor/Zimbra's instructions (or move to a supported release), as required by CISA's KEV listing and BOD 22-01 guidance for federal agencies. In the interim, restrict who can reach the /h/autoSaveDraft handler, review logs for suspicious POSTs to that endpoint and for injected drafts, and hunt for indicators of compromise such as unexpected mailbox rules or account activity.
| Synacor Zimbra Collaboration Suite (ZCS) | 8.8.15 (per the CVE description; no other ranges specified in the data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.
- Affected
- Synacor Zimbra Collaboration Suite (ZCS)
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- synacor
- Products
- zimbra collaboration suite
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H