VDB
CVE-2024-45512
CVE-2024-45512
PUBLISHED
CVSS 8.5 HIGH
An issue was discovered in webmail in Zimbra Collaboration (ZCS) through 10.1. An attacker can exploit this vulnerability by creating a folder in the Briefcase module with a malicious payload and sharing it with a victim. When the victim interacts with the folder share notification, the malicious script executes in their browser. This stored Cross-Site Scripting (XSS) vulnerability can lead to unauthorized actions within the victim's session.
EPSS 0.38% · 31.9th percentile
Risk Scores
CVSS 4.0
8.5
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.38%
31.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| synacor | zimbra_collaboration_suite | 0, 10.0.0, 9.0.0 |
Timeline
- Sep 5, 2024 CVE Published
- Nov 21, 2024 PoC Published
- Nov 21, 2024 CVE Updated
- Nov 22, 2024 EPSS Score
- Dec 11, 2024 EPSS Score
- Dec 28, 2024 EPSS Score
- Jan 15, 2025 EPSS Score
- Feb 1, 2025 EPSS Score
- Feb 19, 2025 EPSS Score
- Mar 9, 2025 EPSS Score
- Mar 26, 2025 EPSS Score
- Apr 1, 2025 Coalition ESS Score
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-45512 advisory
- https://wiki.zimbra.com/wiki/Security_Center url
- https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.9#Security_Fixes url
- https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.1#Security_Fixes url
- https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P41#Security_Fixes url
- https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy url
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P46 advisory
- https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.9 advisory
- https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P41 advisory
- https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.1 advisory