VDB
CVE-2024-45513
CVE-2024-45513
PUBLISHED
CVSS 8.600000381469727 HIGH
An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A stored Cross-Site Scripting (XSS) vulnerability exists in the /modern/contacts/print endpoint of Zimbra webmail. This allows an attacker to inject and execute arbitrary JavaScript code in the context of the victim's browser when a crafted vCard (VCF) file is processed and printed. This could lead to unauthorized actions within the victim's session.
EPSS 0.39% · 32.0th percentile
Risk Scores
CVSS 4.0
8.600000381469727
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.39%
32.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| synacor | zimbra_collaboration_suite | 0, 10.0.0, 9.0.0 |
Timeline
- Sep 5, 2024 CVE Published
- Nov 21, 2024 PoC Published
- Nov 22, 2024 EPSS Score
- Dec 10, 2024 EPSS Score
- Dec 28, 2024 EPSS Score
- Jan 14, 2025 EPSS Score
- Feb 1, 2025 EPSS Score
- Feb 18, 2025 EPSS Score
- Mar 7, 2025 EPSS Score
- Mar 25, 2025 EPSS Score
- Apr 2, 2025 Coalition ESS Score
- Apr 11, 2025 EPSS Score
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-45513 advisory
- https://wiki.zimbra.com/wiki/Security_Center url
- https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.9#Security_Fixes url
- https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.1#Security_Fixes url
- https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P41#Security_Fixes url
- https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy url
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P46 advisory
- https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.9 advisory
- https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P41 advisory
- https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.1 advisory