ZeroHour

CVE-2023-37580

KEVmass

Stored Cross-Site Scripting (XSS) in Synacor Zimbra Collaboration Suite (ZCS)

CISA: Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

CVSS 3.1
6.1 medium
EPSS
47%p99
Published
()
KEV added
AI analysis

CVE-2023-37580 is a cross-site scripting flaw (CWE-79) in Synacor Zimbra Collaboration Suite's webmail interface, publicly described as a stored XSS in which attacker-supplied content persists and executes in victims' browsers. An attacker delivers crafted content (typically a malicious email or message) that, when viewed by a user in the Zimbra webmail client, runs attacker-controlled JavaScript within that user's authenticated session. Successful execution impacts the confidentiality and integrity of the victim's mailbox: the attacker can steal session cookies or credentials, read or alter mail, and act as the user. Any organization running a vulnerable ZCS release is affected, including self-hosted on-premises deployments and providers hosting Zimbra webmail for customers. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-07-27, confirming exploitation in the wild (ransomware association unknown), while no public proof-of-concept is posted, CVSS is not yet scored, and EPSS assigns a 46.7% probability of exploitation within 30 days (99th percentile).

What to do: Apply the latest ZCS patch release addressing CVE-2023-37580 per the Synacor/Zimbra security advisory, as CISA's required action directs, or discontinue use of the affected deployment if mitigation is unavailable; because the flaw is on the KEV list, prioritize internet-facing webmail servers. While patching is pending, restrict webmail exposure (VPN or IP allowlisting) and review webmail and mail-delivery logs for signs of exploitation. Confirm the installed ZCS version and applied patch level against the vendor advisory, since this dataset does not list fixed version numbers.

Affected
Synacor Zimbra Collaboration Suite (ZCS)
Estimated exposure
masstens of thousands of internet-exposed Zimbra servers (order of 10,000–100,000) serving millions of mailboxes in aggregate (estimate) — Internet-wide scans (Censys/Shodan) have repeatedly shown tens of thousands of exposed Zimbra instances, and Zimbra's large installed base (200,000+ reported business customers) implies aggregate user counts well above one million, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.

CISA Known Exploited Vulnerability
Affected
Synacor Zimbra Collaboration Suite (ZCS)
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
synacor
Products
zimbra collaboration suite
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news