VDB

CVE-2024-45512

CVE-2024-45512 PUBLISHED CVSS 8.5 HIGH

An issue was discovered in webmail in Zimbra Collaboration (ZCS) through 10.1. An attacker can exploit this vulnerability by creating a folder in the Briefcase module with a malicious payload and sharing it with a victim. When the victim interacts with the folder share notification, the malicious script executes in their browser. This stored Cross-Site Scripting (XSS) vulnerability can lead to unauthorized actions within the victim's session.

EPSS 0.38% · 31.9th percentile

Risk Scores

CVSS 4.0
8.5
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.38%
31.9th percentile

Affected Products

VendorProductVersions
n/an/an/a
synacorzimbra_collaboration_suite0, 10.0.0, 9.0.0

Timeline

  • Sep 5, 2024 CVE Published
  • Nov 21, 2024 PoC Published
  • Nov 21, 2024 CVE Updated
  • Nov 22, 2024 EPSS Score
  • Dec 11, 2024 EPSS Score
  • Dec 28, 2024 EPSS Score
  • Jan 15, 2025 EPSS Score
  • Feb 1, 2025 EPSS Score
  • Feb 19, 2025 EPSS Score
  • Mar 9, 2025 EPSS Score
  • Mar 26, 2025 EPSS Score
  • Apr 1, 2025 Coalition ESS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›