ZeroHour

CVE-2025-48700

KEVlarge

Cross-Site Scripting in Synacor Zimbra Collaboration Suite Classic UI

CISA: Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

CVSS 3.1
6.1 medium
EPSS
2%p76
Published
()
KEV added
AI analysis

Zimbra Collaboration Suite (ZCS) 8.8.15, 9.0, 10.0, and 10.1 contain a cross-site scripting (XSS) flaw in the Classic UI caused by insufficient sanitization of HTML email content, involving crafted tag structures and attribute values that use @import directives and other script injection vectors. An attacker triggers it simply by getting a user to view a crafted email message in the Classic UI, with no additional user interaction required. Successful exploitation executes arbitrary JavaScript within the victim's session, potentially exposing sensitive mailbox information or enabling unauthorized actions under the victim's identity. Any organization running the affected ZCS branches — particularly internet-facing mail servers whose users receive untrusted email — is in scope. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-20, confirming active exploitation in the wild; no public proof-of-concept is known, and EPSS puts 30-day exploitation probability at about 1.7%.

What to do: Upgrade ZCS to the latest patched builds of the affected 8.8.15/9.0/10.0/10.1 branches per Synacor/Zimbra's security advisory (no specific fixed version is listed here); federal agencies must apply vendor mitigations per BOD 22-01 or discontinue use. Because the flaw is specific to the Classic UI, having users work in the Modern UI instead of the Classic UI reduces exposure until patching is complete. Review mail server and web client logs for users who viewed suspicious HTML-formatted messages as an indicator of targeting.

Affected
Synacor Zimbra Collaboration Suite (ZCS) Classic UI8.8.15, 9.0, 10.0, and 10.1
Estimated exposure
largeon the order of tens of thousands of internet-exposed Zimbra servers — Public internet-wide scans have historically shown tens of thousands of exposed Zimbra Collaboration Suite mail servers, and each server typically serves many mail users, which places this flaw's plausible blast radius in the 10k–100k…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information. This issue arises from insufficient sanitization of HTML content, specifically involving crafted tag structures and attribute values that include an @import directive and other script injection vectors. The vulnerability is triggered when a user views a crafted e-mail message in the Classic UI, requiring no additional user interaction.

CISA Known Exploited Vulnerability
Affected
Synacor Zimbra Collaboration Suite (ZCS)
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
synacor
Products
zimbra collaboration suite
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news