CVE-2024-27443

Published Aug 12, 2024

Last updated 24 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-27443 is a Cross-Site Scripting (XSS) vulnerability found in the CalendarInvite feature of the Zimbra Collaboration Suite (ZCS) classic webmail interface. This vulnerability exists because of improper input validation when handling the calendar header in email messages. An attacker can exploit this flaw by sending a specially crafted email containing a malicious calendar header with an embedded XSS payload. When a user views the email in the Zimbra classic web interface, the malicious code is executed within their browser, potentially allowing the attacker to compromise the user's session and execute arbitrary JavaScript code.

Description
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code.
Source
cve@mitre.org
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
6.1
Impact score
2.7
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Severity
MEDIUM

Known exploits

Data from CISA

Vulnerability name
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
Exploit added on
May 19, 2025
Exploit action due
Jun 9, 2025
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

nvd@nist.gov
CWE-79
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-79

Social media

Hype score
Not currently trending
  1. Cross Site Scripting - Zimbra Collaboration (CVE-2024-27443) vulnerability. ESET discovered attacks in 2024 but only disclosed this on May 15, 2025. #Zimbra #ESET ➡️ https://t.co/gVBYIgAbNN https://t.co/qcyEsAYmDH

    @leonov_av

    3 Jun 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. A critical XSS vulnerability, CVE-2024-27443, in Zimbra Collaboration Suite’s CalendarInvite feature is actively being exploited, potentially by the Sednit hacking group.https://t.co/dRyM5KgkmC

    @blackwired32799

    26 May 2025

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Zimbra CVE-2024-27443 XSS Flaw Hits 129K Servers, Sednit Suspected https://t.co/PbE91KXppy via @HackRead

    @newsoft53759560

    26 May 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Zimbra CVE-2024-27443 XSS Flaw Hits 129K Servers, Sednit Suspected - Hackread https://t.co/Cud7ZEW3EV #AgenticAI

    @EpicPlain

    25 May 2025

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Zimbra CVE-2024-27443 XSS Flaw Hits 129K Servers, Sednit Suspected - Hackread https://t.co/Cud7ZEW3EV #CyberSecurity

    @EpicPlain

    25 May 2025

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Zimbra CVE-2024-27443 XSS Flaw Hits 129K Servers, Sednit Suspected https://t.co/yfTL4foXOg #ransomware #cybersecurityawareness #artificialintelligence #exploit #zerotrust #zeroday #infosecurity #threatintelligence

    @Rajaaaaa07_

    24 May 2025

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Zimbra CVE-2024-27443 XSS Flaw Hits 129K Servers, Sednit Suspected https://t.co/cLJU0NqP8k #infosec #security

    @NotTruppi

    24 May 2025

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2024-27443 #Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability https://t.co/PZ8GOsOaGa

    @ScyScan

    22 May 2025

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 STRIKE Threat Intel Advisory – CVE-2024-27443 🚨 SecurityScorecard’s STRIKE team is tracking active exposure of CVE-2024-27443 — a medium-severity vulnerability currently being exploited in the wild and is found to be targeting government entities and defense comp

    @security_score

    20 May 2025

    122 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2024-27443 #Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability https://t.co/PZ8GOsOIvI

    @ScyScan

    20 May 2025

    62 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. #APT28 Different XSS vulnerabilities being used to target additional webmail software: Horde, MDaemon, and Zimbra. Roundcube CVE-2020-35730 CVE-2023-43770 MDaemon CVE-2024-11182 Outlook Elevation of Privilege Vul CVE-2023-23397 Zimbra CVE-2024-27443 https://t.co/VX2gyK5WkH https:

    @blackorbird

    16 May 2025

    3161 Impressions

    22 Retweets

    63 Likes

    23 Bookmarks

    0 Replies

    0 Quotes

Configurations