ZeroHour

CVE-2023-34192

KEVlarge1

Authenticated XSS in Synacor Zimbra Collaboration Suite 8.8.15 Exploited in the Wild

CISA: Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

CVSS 3.1
9.0 critical
EPSS
77%p100
Published
()
KEV added
AI analysis

CVE-2023-34192 is a critical (CVSS 3.1: 9.0) cross-site scripting (CWE-79) flaw in Synacor Zimbra Collaboration Suite (ZCS) 8.8.15. A remote, authenticated attacker submits a crafted script through the /h/autoSaveDraft endpoint (the autosave-draft handler of the web client), and because the vulnerability requires user interaction and changes scope, the script can execute in another user's browser session. By running code/actions in the security context of the victim's session, the attacker gains high-impact access to confidentiality, integrity, and availability (C:H/I:H/A:H per the CVSS vector). Organizations running ZCS 8.8.15 are affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-02-25 amid reported active exploitation, and EPSS is at 77.3% (100th percentile), though no public proof-of-concept is known.

What to do: Upgrade ZCS 8.8.15 deployments to the latest available patch release per Synacor/Zimbra's instructions (or move to a supported release), as required by CISA's KEV listing and BOD 22-01 guidance for federal agencies. In the interim, restrict who can reach the /h/autoSaveDraft handler, review logs for suspicious POSTs to that endpoint and for injected drafts, and hunt for indicators of compromise such as unexpected mailbox rules or account activity.

Affected
Synacor Zimbra Collaboration Suite (ZCS)8.8.15 (per the CVE description; no other ranges specified in the data)
Estimated exposure
largeon the order of tens of thousands of internet-exposed Zimbra servers (roughly 10k–100k affected deployments) — Zimbra is a widely deployed on-premises email/collaboration platform and historical public internet scans have repeatedly shown tens of thousands of exposed Zimbra servers, with the long-lived 8.8.15 branch among the most commonly run…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.

CISA Known Exploited Vulnerability
Affected
Synacor Zimbra Collaboration Suite (ZCS)
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
synacor
Products
zimbra collaboration suite
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

In the news