CVE-2024-27443

Published Aug 12, 2024

Last updated 6 months ago

Overview

Description
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code.
Source
cve@mitre.org
NVD status
Analyzed
Products
collaboration

Risk scores

CVSS 3.1

Type
Primary
Base score
6.1
Impact score
2.7
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Severity
MEDIUM

Known exploits

Data from CISA

Vulnerability name
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
Exploit added on
May 19, 2025
Exploit action due
Jun 9, 2025
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

nvd@nist.gov
CWE-79
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-79

Social media

Hype score
Not currently trending
  1. 🚨 CVE-2024-27443 - medium 🚨 Zimbra Collaboration - Cross-Site Scripting (XSS) > An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scri... 👾 https://t.co/DNE3SkUOcp @pdnuclei #NucleiTemplates #cve

    @pdnuclei_bot

    31 Oct 2025

    112 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  2. Cross Site Scripting - Zimbra Collaboration (CVE-2024-27443) vulnerability. ESET discovered attacks in 2024 but only disclosed this on May 15, 2025. #Zimbra #ESET ➡️ https://t.co/gVBYIgAbNN https://t.co/qcyEsAYmDH

    @leonov_av

    3 Jun 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. A critical XSS vulnerability, CVE-2024-27443, in Zimbra Collaboration Suite’s CalendarInvite feature is actively being exploited, potentially by the Sednit hacking group.https://t.co/dRyM5KgkmC

    @blackwired32799

    26 May 2025

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Zimbra CVE-2024-27443 XSS Flaw Hits 129K Servers, Sednit Suspected https://t.co/PbE91KXppy via @HackRead

    @newsoft53759560

    26 May 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Zimbra CVE-2024-27443 XSS Flaw Hits 129K Servers, Sednit Suspected - Hackread https://t.co/Cud7ZEW3EV #AgenticAI

    @EpicPlain

    25 May 2025

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Zimbra CVE-2024-27443 XSS Flaw Hits 129K Servers, Sednit Suspected - Hackread https://t.co/Cud7ZEW3EV #CyberSecurity

    @EpicPlain

    25 May 2025

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Zimbra CVE-2024-27443 XSS Flaw Hits 129K Servers, Sednit Suspected https://t.co/yfTL4foXOg #ransomware #cybersecurityawareness #artificialintelligence #exploit #zerotrust #zeroday #infosecurity #threatintelligence

    @Rajaaaaa07_

    24 May 2025

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Zimbra CVE-2024-27443 XSS Flaw Hits 129K Servers, Sednit Suspected https://t.co/cLJU0NqP8k #infosec #security

    @NotTruppi

    24 May 2025

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2024-27443 #Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability https://t.co/PZ8GOsOaGa

    @ScyScan

    22 May 2025

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🚨 STRIKE Threat Intel Advisory – CVE-2024-27443 🚨 SecurityScorecard’s STRIKE team is tracking active exposure of CVE-2024-27443 — a medium-severity vulnerability currently being exploited in the wild and is found to be targeting government entities and defense comp

    @security_score

    20 May 2025

    122 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2024-27443 #Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability https://t.co/PZ8GOsOIvI

    @ScyScan

    20 May 2025

    62 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. #APT28 Different XSS vulnerabilities being used to target additional webmail software: Horde, MDaemon, and Zimbra. Roundcube CVE-2020-35730 CVE-2023-43770 MDaemon CVE-2024-11182 Outlook Elevation of Privilege Vul CVE-2023-23397 Zimbra CVE-2024-27443 https://t.co/VX2gyK5WkH https:

    @blackorbird

    16 May 2025

    3161 Impressions

    22 Retweets

    63 Likes

    23 Bookmarks

    0 Replies

    0 Quotes

Configurations